CVE-2025-15227: WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Read
Published Dec 29, 2025
·Updated
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
Affected Software
2 affected components
WELLTEND TECHNOLOGY BPMFlowWebkit
WELLTEND BPMFlowWebkit<5.0.5
Remediation
Information
Update to version 5.0.5 or later.
Event History
Dec 29, 2025
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-15227?
CVE-2025-15227 is classified as a critical vulnerability due to its potential for unauthorized access to sensitive system files.
2
How do I fix CVE-2025-15227?
To mitigate CVE-2025-15227, upgrade to the latest version of BPMFlowWebkit that addresses this vulnerability as soon as possible.
3
Who is affected by CVE-2025-15227?
CVE-2025-15227 affects all versions of BPMFlowWebkit developed by WELLTEND TECHNOLOGY.
4
What is the nature of the vulnerability in CVE-2025-15227?
CVE-2025-15227 is an Arbitrary File Read vulnerability that allows attackers to exploit Absolute Path Traversal.
5
Can CVE-2025-15227 be exploited remotely?
Yes, CVE-2025-15227 can be exploited by unauthenticated remote attackers.