CVE-2025-60880 is an authenticated stored Cross-Site Scripting (XSS) vulnerability affecting Bagisto 2.3.6's admin panel, specifically within the product creation path. An authenticated administrator can upload a malicious SVG file, embedding JavaScript that executes in the browser of other administrators. This vulnerability carries a high CVSS score of 8.3, indicating a significant risk of session hijacking, data theft, or unauthorized actions due to its network-based attack vector and high impact on confidentiality and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and there is no evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.6CPE matchmatch criteria | cpe:2.3:a:webkul:bagisto:2.3.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.