A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Performing manipulation results in authorization bypass. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 24 Nov 2025 21:30:00 +0900

Type Values Removed Values Added
First Time appeared Bdtask pharmacare
CPEs cpe:2.3:a:bdtask:pharmacare:*:*:*:*:*:*:*:*
Vendors & Products Bdtask pharmacare

Fri, 31 Oct 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Oct 2025 19:30:00 +0900

Type Values Removed Values Added
First Time appeared Bdtask
Bdtask pharmacy Management System
Vendors & Products Bdtask
Bdtask pharmacy Management System

Mon, 27 Oct 2025 23:45:00 +0900

Type Values Removed Values Added
Description A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Performing manipulation results in authorization bypass. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Bdtask Pharmacy Management System User Profile edit_user authorization
Weaknesses CWE-285
CWE-639
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-10-30T14:16:30.330Z

Reserved: 2025-10-26T16:30:37.534Z

Link: CVE-2025-12288

cve-icon Vulnrichment

Updated: 2025-10-27T17:05:53.011Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-27T15:15:37.117

Modified: 2025-11-24T12:16:12.017

Link: CVE-2025-12288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-28T19:24:35Z

Weaknesses