Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to their own shopping cart by manipulating the order ID parameter. This exposes sensitive purchase information and enables potential fraud. Version 2.3.10 patches the issue.
History

Fri, 02 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
Description Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to their own shopping cart by manipulating the order ID parameter. This exposes sensitive purchase information and enables potential fraud. Version 2.3.10 patches the issue.
Title Bagisto has IDOR in Customer Order Reorder Functionality
Weaknesses CWE-284
CWE-639
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-02T21:30:38.620Z

Reserved: 2025-12-29T03:00:29.277Z

Link: CVE-2026-21447

cve-icon Vulnrichment

Updated: 2026-01-02T21:30:32.295Z

cve-icon NVD

Status : Received

Published: 2026-01-02T21:15:58.773

Modified: 2026-01-02T21:15:58.773

Link: CVE-2026-21447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.