A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit Profile Page. This manipulation causes unrestricted upload. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
History

Fri, 21 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:bdtask:flight_booking_software:4.0:*:*:*:*:*:*:*

Mon, 17 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Nov 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Bdtask
Bdtask flight Booking Software
Vendors & Products Bdtask
Bdtask flight Booking Software

Sun, 16 Nov 2025 05:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit Profile Page. This manipulation causes unrestricted upload. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Title Bdtask Flight Booking Software Edit Profile edit unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-11-16T05:32:05.486Z

Updated: 2025-11-17T19:00:34.257Z

Reserved: 2025-11-15T06:33:51.549Z

Link: CVE-2025-13238

cve-icon Vulnrichment

Updated: 2025-11-17T19:00:31.116Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-16T06:15:42.207

Modified: 2025-11-21T22:00:43.200

Link: CVE-2025-13238

cve-icon Redhat

No data.