Executive brief
A security vulnerability exists in the Bdtask Multi-Store Inventory Management System, a software used for tracking stock and sales across multiple locations. An attacker can upload malicious files to the server, which could lead to unauthorized access or full control over the system. This could result in the theft of business data, disruption of inventory operations, or the installation of malware.
Technical details
An unrestricted file upload vulnerability exists in Bdtask Multi-Store Inventory Management System 1.0 within the 'Upload' function of the 'application/modules/dashboard/controllers/Module.php' file. The vulnerability is triggered by manipulating the 'module' argument, which fails to properly validate file types or extensions. A remote attacker with low-level privileges can exploit this to upload and execute malicious scripts (such as a PHP web shell) on the server. Public exploit code has been released, increasing the risk of active exploitation.
Affected products
- Bdtask Multi-Store Inventory Management System 1.0
Timeline
- 2026-05-31: disclosed
- 2026-05-31: advisory