CVE-2025-12287 is a high-severity SQL injection vulnerability affecting Bdtask Wholesale Inventory Control and Inventory Management System up to version 20251013. This flaw allows remote, authenticated attackers to manipulate the 'first_name' or 'last_name' arguments within the /Admin_dashboard/edit_profile function, leading to full compromise of confidentiality, integrity, and availability. While publicly disclosed, there is currently no evidence of active exploitation, nor are there readily available exploit modules in common frameworks. The vendor has not responded to the disclosure, and community discussion surrounding this CVE is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-10-13CPE matchmatch criteria | cpe:2.3:a:bdtask:wholesale:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.