CVE-2025-15227

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

high 7.5 CVSS 3.1
Published: Dec 29, 2025
Modified: Dec 31, 2025
Vendor: Welltend
Product: Bpmflowwebkit

Description

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

References

Related CVEs