CVE-2026-6744
MEDIUMBagisto Downloadable Link copy server-side request forgery
Title source: cnaDescription
A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and explains: "We already replied on the github advisories. All the security issues are addressed through security advisory. We will fix this in our upcomming releases."
References (4)
Core 4
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-358435 | Bagisto Downloadable Link copy server-side request forgery
https://vuldb.com/vuln/358435
Signature, Permissions Required signature
permissions-required
VDB-358435 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/358435/cti
Third Party Advisory third-party-advisory
Submit #794680 | bagisto v2.3.15 Server-Side Request Forgery
https://vuldb.com/submit/794680
Scores
CVSS v3
6.3
EPSS
0.0020
EPSS Percentile
10.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (17)
None/Bagisto
2.3.0
None/Bagisto
2.3.1
None/Bagisto
2.3.10
None/Bagisto
2.3.11
None/Bagisto
2.3.12
None/Bagisto
2.3.13
None/Bagisto
2.3.14
None/Bagisto
2.3.15
None/Bagisto
2.3.2
None/Bagisto
2.3.3
... and 7 more
Published
Apr 21, 2026
Tracked Since
Apr 22, 2026