PT-2025-43962 · Unknown · Wholesale Inventory Control/Inventory Management System
4M3Rr0R
·
Published
2025-10-27
·
Updated
2025-11-24
·
CVE-2025-12287
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bdtask Wholesale Inventory Control and Inventory Management System versions prior to 20251014
Description
A security issue exists in Bdtask Wholesale Inventory Control and Inventory Management System. Manipulation of the
first name and last name arguments within an unknown function of the file '/Admin dashboard/edit profile' can lead to SQL injection. The attack can be launched remotely. The details of the exploit have been publicly disclosed. The vendor was notified but did not respond.Recommendations
Versions prior to 20251014 should be updated. As a temporary workaround, restrict or carefully validate input to the
first name and last name arguments in the '/Admin dashboard/edit profile' file.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wholesale Inventory Control/Inventory Management System