{"id":"CVE-2019-14933","aliases":["GHSA-pgwp-f3xh-m24g"],"url":"https://o3.security/vulnerability/CVE-2019-14933","summary":"Bagisto CSRF Vulnerability","details":"Bagisto before 0.1.5 allows CSRF under `/admin` URIs.","published":"2019-08-11T21:15:10.860Z","modified":"2026-08-07T15:18:00.985142Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00648,"percentile":0.48092,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"bagisto/bagisto","fixedVersion":"0.1.5"}],"fix":{"url":"https://github.com/bagisto/bagisto/pull/808","label":"bagisto/bagisto#808"},"references":[{"type":"ADVISORY","url":"https://forums.bagisto.com/category/1/announcements"},{"type":"REPORT","url":"https://github.com/bagisto/bagisto/issues/750"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14933"},{"type":"WEB","url":"https://github.com/bagisto/bagisto/pull/808"},{"type":"PACKAGE","url":"https://github.com/bagisto/bagisto"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:18:00.985142Z"}}