Sceawere
Vulnerability Detail
CVE-2026-19837UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Webkul Bagisto Customer Search Information Disclosure
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.7
- Creation Date
- 2h ago
- Vendor
- Webkul
- Product
- Bagisto
- Attack Type
- Information Disclosure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.7",
"pubDate": "2026-08-14T16:16:54.900Z",
"pubdate": "2026-08-14T16:16:54.900Z",
"executiveSummary": "An information disclosure vulnerability has been identified in Webkul Bagisto up to version 2.4.4, specifically within the Customer Search component.\nThe vulnerability resides in the handling of the Query argument processed via the /admin/customers/search endpoint.\nA remote, unauthenticated or authenticated attacker capable of interacting with the administrative customer search functionality can manipulate the Query parameter to elicit unintended data exposure.\nSuccessful exploitation of this flaw leads to the unauthorized extraction of sensitive information accessible within the scope of the customer search functionality.\nThe risk implication centers on the potential leakage of confidential customer records or system data, which could facilitate further reconnaissance or subsequent attacks against the application.\nPublic availability of exploit material increases the urgency for deployment of corrective updates.\nThe vendor has acknowledged the issue, noting that related items are managed through their internal security and development lifecycle, with patches slated for upcoming product releases.",
"technicalDetails": "The vulnerability is an information disclosure flaw affecting Webkul Bagisto up to version 2.4.4.\nThe affected component is the Customer Search feature, specifically handling requests sent to the /admin/customers/search route.\nThe root cause stems from improper input sanitization, validation, or inadequate access controls applied to the Query parameter during search query execution.\nWhen a user or remote attacker submits a specially crafted string via the Query argument, the backend application fails to properly restrict the query scope or filter out sensitive database fields and records.\nAttack flow begins with the adversary crafting a malicious HTTP request targeting the /admin/customers/search endpoint.\nThe attacker injects payload variations into the Query parameter, manipulating the search criteria to bypass intended application constraints.\nUpon receiving the request, the underlying controller processes the unsanitized or improperly constrained Query input and executes a database query or data retrieval operation.\nThe application subsequently returns the resulting dataset containing sensitive information within the HTTP response to the client.\nDepending on the administrative access requirements of the endpoint, exploitation may require low-privileged or unauthenticated remote network access, exposing the application to data harvesting.\nPost-exploitation impact includes the unauthorized extraction of customer details, personally identifiable information (PII), or other internal data structures returned by the search mechanism, aiding threat actors in mapping the database schema and gathering intelligence for advanced operations."
}