PT-2025-43962 · Unknown · Wholesale Inventory Control/Inventory Management System

4M3Rr0R

·

Published

2025-10-27

·

Updated

2025-11-24

·

CVE-2025-12287

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bdtask Wholesale Inventory Control and Inventory Management System versions prior to 20251014
Description A security issue exists in Bdtask Wholesale Inventory Control and Inventory Management System. Manipulation of the first name and last name arguments within an unknown function of the file '/Admin dashboard/edit profile' can lead to SQL injection. The attack can be launched remotely. The details of the exploit have been publicly disclosed. The vendor was notified but did not respond.
Recommendations Versions prior to 20251014 should be updated. As a temporary workaround, restrict or carefully validate input to the first name and last name arguments in the '/Admin dashboard/edit profile' file.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-12287

Affected Products

Wholesale Inventory Control/Inventory Management System