CVE-2026-6744

A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and explains: "We already replied on the github advisories. All the security issues are addressed through security advisory. We will fix this in our upcomming releases."
Configurations

No configuration.

History

21 Apr 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 19:16

Updated : 2026-04-29 01:00


NVD link : CVE-2026-6744

Mitre link : CVE-2026-6744

CVE.ORG link : CVE-2026-6744


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)