Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Bagisto - CVE-2025-62414
Published: April 25, 2026
Bagisto
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of script-related HTML tags in the create new customer feature in the admin panel when rendering customer data in the admin UI. A remote privileged user can inject malicious JavaScript into customer input fields to execute arbitrary script in a victim's browser.
User interaction is required when an admin or another user views the injected customer record.