CVE-2026-6744

MEDIUM

Bagisto Downloadable Link copy server-side request forgery

Title source: cna
STIX 2.1

Description

A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and explains: "We already replied on the github advisories. All the security issues are addressed through security advisory. We will fix this in our upcomming releases."

References (4)

Core 4
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-358435 | Bagisto Downloadable Link copy server-side request forgery
https://vuldb.com/vuln/358435
Signature, Permissions Required signature permissions-required
VDB-358435 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/358435/cti
Third Party Advisory third-party-advisory
Submit #794680 | bagisto v2.3.15 Server-Side Request Forgery
https://vuldb.com/submit/794680

Scores

CVSS v3 6.3
EPSS 0.0020
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (17)
None/Bagisto 2.3.0
None/Bagisto 2.3.1
None/Bagisto 2.3.10
None/Bagisto 2.3.11
None/Bagisto 2.3.12
None/Bagisto 2.3.13
None/Bagisto 2.3.14
None/Bagisto 2.3.15
None/Bagisto 2.3.2
None/Bagisto 2.3.3
... and 7 more
Published Apr 21, 2026
Tracked Since Apr 22, 2026