CyberRota Analysis
AI-GeneratedThe Webkul Bagisto platform, up to version 2.4.4, contains a vulnerability in the Admin Customer Impersonation Feature that allows for remote authorization bypass through manipulation of the argument ID in the login-as-customer function. This could potentially enable unauthorized access to customer accounts. Organizations using affected versions should prioritize remediation to mitigate the risk of exploitation, especially as the vulnerability has been publicly disclosed.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."