---
id: CVE-2025-12288
title: A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4
summary: >-
  A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4.
  Affected is an unknown function of the file /user/edit_user/ of the component
  User Profile Handler. Performing manipulation results in authorization bypass.
  Rem…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-285
  - CWE-639
  - CWE-639
vendor: bdtask
product: pharmacare
affected:
  - pharmacare <= 9.4
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12288'
references:
  - url: 'https://github.com/4m3rr0r/PoCVulDb/blob/main/CVE-2025-12288.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.329956'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.329956'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.674883'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00477
epssPercentile: 0.39165
ingestedAt: '2026-10-08T11:31:27.636Z'
---

## Overview

A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file /user/edit_user/ of the component User Profile Handler. Performing manipulation results in authorization bypass. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `pharmacare <= 9.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
