Metrics
Affected Vendors & Products
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bdtask
Bdtask flight Booking Software |
|
| Vendors & Products |
Bdtask
Bdtask flight Booking Software |
Mon, 27 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the component Package Information Module. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Bdtask Flight Booking Software Package Information package-information unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-27T04:32:07.968Z
Updated: 2025-10-27T20:05:20.283Z
Reserved: 2025-10-25T16:21:51.792Z
Link: CVE-2025-12223
Updated: 2025-10-27T20:05:16.633Z
Status : Awaiting Analysis
Published: 2025-10-27T05:15:38.027
Modified: 2025-10-27T13:19:49.063
Link: CVE-2025-12223
No data.