{"id":"CVE-2026-21448","aliases":["GHSA-5j4h-4f72-qpm6"],"url":"https://o3.security/vulnerability/CVE-2026-21448","summary":"Bagisto has Normal & Blind SSTI from low-privilege user when ordering product","details":"### Summary\nSSTI when normal customer orders any product in add address step can inject value run in admin view.\n### Details\n`As normal user`\n1. Go to `http://127.0.0.1:8000/`\n2. Add order to cart and continue to checkout \n3. In step of add address inject this value {{7*7}} in any input\n\n`As admin`\n1. Go to `http://127.0.0.1:8000/admin/sales/orders`\n2. And notice the vlaue appear in admin view 49\n\n`As normal user`\n3. Go to add address normally `http://127.0.0.1:8000/customer/account/addresses/create` and inject {{7*7}} on it and will notice it appear 49\n<img width=\"1868\" height=\"868\" alt=\"image\" src=\"https://github.com/user-attachments/assets/279627e9-6361-4d39-a500-0fc20e163d25\" />\n\n\n### PoC\n - Video attached with the report:  https://github.com/user-attachments/assets/a814b30c-a3e2-4a40-8644-336e21e60d0d\n\n\n### Impact\n- Can lead to RCE","published":"2026-01-02T20:18:08.519Z","modified":"2026-08-12T03:51:47.575478093Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"bagisto/bagisto","fixedVersion":"2.3.10"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21448.json"},{"type":"ADVISORY","url":"https://github.com/bagisto/bagisto/security/advisories/GHSA-5j4h-4f72-qpm6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21448"},{"type":"PACKAGE","url":"https://github.com/bagisto/bagisto"},{"type":"WEB","url":"https://github.com/bagisto/bagisto/releases/tag/v2.3.10"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.575478093Z"}}