CVE-2026-6744 | Bagisto up to 2.3.15 Downloadable Link copy server-side request forgery
A vulnerability was found in Bagisto up to 2.3.15. It has been declared as critical. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-6744. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure and explains: “We already replied on the github advisories. All the security issues are addressed through security advisory. We will fix this in our upcomming releases.”VulDB Recent EntriesRead More