Unrestricted Upload Vulnerability in Bdtask Flight Booking Software
CVE-2025-13238
Key Information:
- Vendor
Bdtask
- Status
- Vendor
- CVE Published:
- 16 November 2025
Badges
What is CVE-2025-13238?
A vulnerability in Bdtask Flight Booking Software version 4 allows attackers to exploit an unknown functionality of the Edit Profile Page, specifically through the endpoint '/agent/profile/edit'. This weakness enables the unrestricted uploading of files by unauthorized users, which can lead to further exploitation. The attack can be initiated remotely, posing a significant threat to the security of the system. This issue has been disclosed publicly, and despite the vendor's initial notification, no response has been observed regarding a fix or mitigation.
Affected Version(s)
Flight Booking Software 4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
