Description
A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and explains: "We already replied on the github advisories. All the security issues are addressed through security advisory. We will fix this in our upcomming releases."
Problem types
Timeline
| 2026-04-21: | Advisory disclosed |
| 2026-04-21: | VulDB entry created |
| 2026-04-21: | VulDB entry last update |
Credits
hai271120 (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/358435 (VDB-358435 | Bagisto Downloadable Link copy server-side request forgery)
vuldb.com/vuln/358435/cti (VDB-358435 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/794680 (Submit #794680 | bagisto v2.3.15 Server-Side Request Forgery)
drive.google.com/..._rUE2Jms5EcIBGSMdrq6Wql/view?usp=sharing