CVE-2025-15228
EUVD-2025-20556329.12.2025, 08:15
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| welltend | bpmflowwebkit | 𝑥 < 5.0.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration