CVE-2025-15228: WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Upload
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15228?
CVE-2025-15228 is classified as a high severity vulnerability due to its potential for arbitrary code execution on the server.
How do I fix CVE-2025-15228?
To mitigate CVE-2025-15228, ensure that file upload functionality is properly restricted and validate file types to prevent unauthorized uploads.
Who is affected by CVE-2025-15228?
CVE-2025-15228 affects users of the BPMFlowWebkit developed by WELLTEND TECHNOLOGY.
What is the impact of CVE-2025-15228?
The impact of CVE-2025-15228 includes the potential for remote attackers to upload malicious files that execute arbitrary code on the server.
Is authentication required to exploit CVE-2025-15228?
No, CVE-2025-15228 allows unauthenticated remote attackers to exploit the vulnerability.