PT-2025-53705 · Welltend Technology · Bpmflowwebkit

Alan Chung

+1

·

Published

2025-12-29

·

Updated

2025-12-31

·

CVE-2025-15228

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BPMFlowWebkit (affected versions not specified)
Description BPMFlowWebkit developed by WELLTEND TECHNOLOGY has an arbitrary file upload issue. This allows unauthenticated remote attackers to upload and execute web shell backdoors, leading to arbitrary code execution on the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-15228

Affected Products

Bpmflowwebkit