CVE-2025-15228

Publication date

2025-12-29 07:18:59

Family

twcert

State

PUBLISHED

Description

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.