Server-Side Template Injection in Bagisto eCommerce Platform
CVE-2025-62416
5.1MEDIUM
What is CVE-2025-62416?
Bagisto, an open-source Laravel eCommerce platform, is vulnerable to Server-Side Template Injection (SSTI) due to insecure handling of user input in product descriptions. This flaw allows users with product creation privileges to inject malicious template expressions. When these expressions are processed by the server’s templating engine, it could lead to severe consequences including Remote Code Execution (RCE). The issue has been rectified in version 2.3.8.
Affected Version(s)
bagisto < 2.3.8