Vulnerability Name: - Bdtask Flight Booking Software 4 Edit Profile Page /agent/profile/edit Unrestricted Upload CVE ID: - CVE-2025-13238 Severity: - Critical Affected Product: - Bdtask Flight Booking Software 4 Vulnerable Functionality: - Unknown functionality in the file /agent/profile/edit of the component "Edit Profile Page" Impact: - Unrestricted upload Attack Vector: - Can be launched remotely Exploit Status: - Exploit available Vendor Response: - Vendor contacted but did not respond CWE Classification: - CWE-434 Impact on CIA Triad: - Confidentiality, Integrity, Availability MITRE ATT&CK Technique: - T1608.002 Advisory Sharing: - Available for download at github.com