Junglewise Threat Intelligence

CVE-2026-10172: Bdtask Multi-Store Inventory Management System unrestricted upload in Module.php

CVE-2026-10172 · Severity: medium · CVSS 6.3 · Published 2026-05-31

Executive brief

A security vulnerability exists in the Bdtask Multi-Store Inventory Management System, a software used for tracking stock and sales across multiple locations. An attacker can upload malicious files to the server, which could lead to unauthorized access or full control over the system. This could result in the theft of business data, disruption of inventory operations, or the installation of malware.

Technical details

An unrestricted file upload vulnerability exists in Bdtask Multi-Store Inventory Management System 1.0 within the 'Upload' function of the 'application/modules/dashboard/controllers/Module.php' file. The vulnerability is triggered by manipulating the 'module' argument, which fails to properly validate file types or extensions. A remote attacker with low-level privileges can exploit this to upload and execute malicious scripts (such as a PHP web shell) on the server. Public exploit code has been released, increasing the risk of active exploitation.

Affected products

  • Bdtask Multi-Store Inventory Management System 1.0

Timeline

  • 2026-05-31: disclosed
  • 2026-05-31: advisory

References

Related threats