What is CVE-2026-19837?
An information disclosure weakness has been identified in Webkul Bagisto up to version 2.4.4, affecting the `/admin/customers/search` component. A remote attacker can manipulate the `Query` argument to potentially access sensitive data. Users are advised to update to the latest version immediately.
Azərbaycanca: Webkul Bagisto-nun 2.4.4-ə qədər versiyalarında `/admin/customers/search` komponentində məlumat sızması zəifliyi aşkar edilib. Bu, uzaqdan hücumçuya `Query` arqumentini manipulyasiya edərək həssas məlumatlara çıxış əldə etməyə imkan verir. İstifadəçilərə dərhal proqramı ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Webkul Bagisto are affected by CVE-2026-19837?
This vulnerability affects Webkul Bagisto up to version 2.4.4.
What action is recommended to protect against CVE-2026-19837?
Users are advised to update the software to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.