PT-2025-53703 · Welltend Technology · Bpmflowwebkit

Alan Chung

+1

·

Published

2025-12-29

·

Updated

2025-12-31

·

CVE-2025-15227

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions BPMFlowWebkit (affected versions not specified)
Description BPMFlowWebkit developed by WELLTEND TECHNOLOGY has an issue that allows unauthenticated remote attackers to download arbitrary system files by exploiting Absolute Path Traversal. The vulnerability allows for arbitrary file reading.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-15227

Affected Products

Bpmflowwebkit