High severity8.8NVD Advisory· Published Feb 26, 2024· Updated Jun 17, 2026
CVE-2023-36237
CVE-2023-36237
Description
Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bagisto/bagistoPackagist | < 1.3.2 | 1.3.2 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/Ek-Saini/security/blob/main/CSRF-BagistonvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-7p7q-fjfw-v3gfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-36237ghsaADVISORY
- github.com/bagisto/bagisto/commit/265aa14db1490005fa4e0d6fe714835abb689813ghsaWEB
- github.com/bagisto/bagisto/commits/v1.3.2/ghsaWEB
News mentions
0No linked articles in our index yet.