CVE-2025-62414
16.10.2025, 19:15
Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the Create New Customer feature (in the admin panel) is vulnerable to Cross-Site Scripting (XSS). An attacker with access to the admin create-customer form can inject malicious JavaScript payloads into certain input fields. These payloads may later execute in the context of an admins browser or another user viewing the customer data, enabling session theft or admin-level actions. This vulnerability is fixed in 2.3.8.
Awaiting analysis
This vulnerability is currently awaiting analysis.