Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
| Software | From | Fixed in |
|---|---|---|
bagisto / bagisto
|
- | 2.1.0 |
| webkul / bagisto | 1.5.1 | 1.5.1.x |