Description
A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the file /Admin_dashboard/edit_profile. Such manipulation of the argument first_name/last_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2025-10-27
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Bdtask wholesale
CPEs cpe:2.3:a:bdtask:wholesale:*:*:*:*:*:*:*:*
Vendors & Products Bdtask wholesale

Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Bdtask
Bdtask wholesale Inventory Control And Inventory Management System
Vendors & Products Bdtask
Bdtask wholesale Inventory Control And Inventory Management System

Mon, 27 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 20251013. This impacts an unknown function of the file /Admin_dashboard/edit_profile. Such manipulation of the argument first_name/last_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Bdtask Wholesale Inventory Control and Inventory Management System edit_profile sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Bdtask Wholesale Wholesale Inventory Control And Inventory Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-01-07T17:06:41.712Z

Reserved: 2025-10-26T16:30:34.572Z

Link: CVE-2025-12287

cve-icon Vulnrichment

Updated: 2026-01-07T17:06:38.603Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-27T15:15:36.923

Modified: 2025-11-24T12:07:35.847

Link: CVE-2025-12287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-27T22:03:49Z

Weaknesses