CVE-2025-13179 PUBLISHED

Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System cross-site request forgery

Assigner: VulDB
Reserved: 14.11.2025 Published: 14.11.2025 Updated: 14.11.2025

A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects some unknown processing. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor Bdtask
Product Wholesale Inventory Control and Inventory Management System
Versions
  • Version 20250320 is affected
Vendor CodeCanyon
Product Wholesale Inventory Control and Inventory Management System
Versions
  • Version 20250320 is affected

Credits

  • 4m3rr0r (VulDB User) reporter

References

Problem Types

  • Cross-Site Request Forgery CWE
  • Missing Authorization CWE