Script Injection Vulnerability in Bagisto eCommerce Platform
CVE-2025-62418
6.9MEDIUM
What is CVE-2025-62418?
An exploit in Bagisto version 2.3.7 allows an authenticated user with admin privileges to upload malicious SVG files containing JavaScript. When these files are viewed, the embedded scripts execute in the browser context of the user, posing a significant security risk. This issue has been addressed in version 2.3.8.
Affected Version(s)
bagisto < 2.3.8