---
id: CVE-2025-12223
title: A vulnerability was detected in Bdtask Flight Booking Software up to 3.1
summary: >-
  A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This
  affects an unknown part of the file /b2c/package-information of the component
  Package Information Module. The manipulation results in unrestricted upload.
  The…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-284
  - CWE-434
  - CWE-434
vendor: bdtask
product: flight_booking_software
affected:
  - flight_booking_software <= 3.1
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12223'
references:
  - url: 'https://github.com/4m3rr0r/PoCVulDb/blob/main/CVE-2025-12223.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.329893'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.329893'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.673436'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00396
epssPercentile: 0.31706
ingestedAt: '2026-10-08T11:31:27.617Z'
---

## Overview

A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown part of the file /b2c/package-information of the component Package Information Module. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `flight_booking_software <= 3.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
