Server-Side Template Injection in Bagisto eCommerce Platform
CVE-2025-62416

5.1MEDIUM

Key Information:

Vendor

Bagisto

Status
Vendor
CVE Published:
16 October 2025

What is CVE-2025-62416?

Bagisto, an open-source Laravel eCommerce platform, is vulnerable to Server-Side Template Injection (SSTI) due to insecure handling of user input in product descriptions. This flaw allows users with product creation privileges to inject malicious template expressions. When these expressions are processed by the server’s templating engine, it could lead to severe consequences including Remote Code Execution (RCE). The issue has been rectified in version 2.3.8.

Affected Version(s)

bagisto < 2.3.8

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62416 : Server-Side Template Injection in Bagisto eCommerce Platform