Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2025123001121717 | Publication Time | 2025/12/30 13:40 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2025/12/30 13:40 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】Hung Ming Enterprise – Northern Project Technology Department | Arbitrary File Upload (CVE-2025-15228) |
|||
| [Content] Forwarded from TWCERTCC-200-202512-00000017 【Hung Ming Enterprise – Northern Project Technology Department | Arbitrary File Upload】 (CVE-2025-15228, CVSS: 9.8) An Arbitrary File Upload vulnerability exists in BPMFlowWebkit. An unauthenticated remote attacker can upload and execute web shell backdoor programs, thereby executing arbitrary code on the server. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform] BPMFlowWebkit versions earlier than 5.0.5 (exclusive) |
|||
| [Recommended Actions] Please update to version 5.0.5 or later. |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-132-10604-c65aa-1.html |
|||