CVE-2025-13179

MEDIUM

Bdtask Wholesale < 2025-10-16 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20250320. This issue affects some unknown processing. Such manipulation leads to cross-site request forgery. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.332469
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.332469
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.684823
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/4m3rr0r/PoCVulDb/issues/3

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 8.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352 CWE-862
Status published
Products (1)
bdtask/wholesale < 2025-10-16
Published Nov 14, 2025
Tracked Since Feb 18, 2026