An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly.
2025-10-09T16:15:45.480
2025-10-30T14:30:40.043
Analyzed
CVSSv3.1: 6.5 (MEDIUM)