PT-2025-43877 · Unknown · Bdtask Flight Booking

·

CVE-2025-12223

·

Published

2025-10-27

·

Updated

2025-11-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bdtask Flight Booking Software versions prior to 3.2
Description A flaw exists in Bdtask Flight Booking Software that allows for unrestricted file uploads. This issue affects the Package Information Module, specifically within the /b2c/package-information file. The attack can be initiated remotely. The details of the exploit have been publicly released. The vendor was notified but did not provide a response.
Recommendations Update Bdtask Flight Booking Software to version 3.2 or later.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12223

Affected Products

Bdtask Flight Booking