CVE-2025-62416 - CVE House
Back to Database
Status published Medium CVE-2025-62416

bagisto - Server Side Template Injection (SSTI) in Product Description

Vulnerability Description

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with product creation privileges to inject arbitrary template expressions that are evaluated by the backend — potentially leading to Remote Code Execution (RCE) on the server. This vulnerability is fixed in 2.3.8.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62416

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

bagisto
Vulnerable Versions:
< 2.3.8

Timeline

Official Publish: October 16th, 2025
Last Modified: October 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

Weaknesses (CWE)