A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Performing manipulation results in authorization bypass. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bdtask
Bdtask pharmacy Management System |
|
| Vendors & Products |
Bdtask
Bdtask pharmacy Management System |
Mon, 27 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Performing manipulation results in authorization bypass. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Bdtask Pharmacy Management System User Profile edit_user authorization | |
| Weaknesses | CWE-285 CWE-639 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-27T14:32:09.211Z
Updated: 2025-10-27T14:32:09.211Z
Reserved: 2025-10-26T16:30:37.534Z
Link: CVE-2025-12288
No data.
Status : Received
Published: 2025-10-27T15:15:37.117
Modified: 2025-10-27T15:15:37.117
Link: CVE-2025-12288
No data.