CVE-2025-15228

9.8

WELLTEND TECHNOLOGY · BPMFlowWebkit

BPMFlowWebkit contains an arbitrary file upload vulnerability that allows unauthenticated remote attackers to upload web shell backdoors and achieve remote code execution.

Executive summary

A critical arbitrary file upload vulnerability in WELLTEND TECHNOLOGY BPMFlowWebkit allows unauthenticated remote attackers to execute arbitrary code on affected servers.

Vulnerability

The application is susceptible to an unrestricted upload of file with dangerous type (CWE-434), which enables unauthenticated remote attackers to bypass security controls to upload and execute malicious web shells.

Business impact

The ability for an unauthenticated attacker to execute arbitrary code provides full control over the compromised server. Given the CVSS score of 9.8, this vulnerability poses a critical risk of complete system compromise, potential data exfiltration, and lateral movement within the production network.

Remediation

Immediate Action: Update the BPMFlowWebkit software to version 5.0.5 or later immediately to remove the vulnerable file upload functionality.

Proactive Monitoring: Review web server access logs for suspicious file uploads or requests targeting non-public directories that may indicate the presence of a web shell.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block file uploads containing executable extensions or suspicious file signatures until the patch can be applied.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

This vulnerability represents a critical security risk due to the potential for full server takeover by unauthenticated actors. Organizations utilizing BPMFlowWebkit must prioritize the deployment of version 5.0.5 or higher to eliminate the attack vector. If patching is not immediately feasible, restrict network access to the affected interface to prevent external exploitation.

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Analyst report written
  5. Fix documented version 5.0.5 per CVE record

Sources