CVE-2023-36238: Webkul Bagisto
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.
Affected products
- Webkul Bagisto: version 1.5.1 only
Published 2024-03-13. Last modified 2026-06-17.