External risk intelligence

WELLTEND BPMFlowWebkit Arbitrary File Upload Leading to Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-15228

BPMFlowWebkit is a web-based application component. Web applications and their associated processing components are commonly deployed as internet-facing services to facilitate remote access and business process management, making them reachable from the public internet.

Unrestricted File Upload

Welltend Bpmflowwebkit

before 5.0.5

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in WELLTEND TECHNOLOGY's BPMFlowWebkit, which allows unauthenticated attackers to upload and execute malicious code. This could potentially lead to unauthorized control of the server. The main concern is confirming if this specific technology is in use within our environment.

  • Unauthenticated file upload allows server code execution.
  • Confirms if this web technology is in use.
  • Assess relevance and exposure to our systems.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by uploading a malicious file through the BPMFlowWebkit application. Since no authentication is required, an unauthenticated remote attacker can leverage this exposure to upload a web shell. Successful exploitation allows for arbitrary code execution on the server.

  • No authentication needed for access.
  • Upload a web shell backdoor.
  • Achieve arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated remote attackers to upload and execute arbitrary code on the server. This could potentially lead to the compromise of the server's integrity and availability, affecting its intended operations and any data it processes.

  • Server code execution.
  • Remote file upload.
  • Service compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Arbitrary File Upload vulnerability in BPMFlowWebkit requires immediate attention from teams managing web applications and the underlying infrastructure. The first step is to identify all instances of BPMFlowWebkit, determine their exposure and criticality, and assign ownership for remediation planning.

  • Identify and confirm BPMFlowWebkit instances.
  • Verify exposure and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WELLTEND BPMFlowWebkit?

BPMFlowWebkit is a web-based component created by WELLTEND TECHNOLOGY designed for business process management. It is typically integrated into web environments to handle workflows, automate administrative tasks, and manage data processing between users and backend systems.

What does CVE-2025-15228 mean for security?

This vulnerability is classified as an Unrestricted Upload of File with Dangerous Type (CWE-434). In plain terms, the software fails to properly check the types of files uploaded to the server. Because of this, an attacker can bypass security controls to save malicious scripts that the server then executes, granting the attacker control over the system.

How does an attacker trigger this vulnerability?

The flaw is triggered when an attacker sends a specially crafted file upload request to the application. Because the system does not require authentication, the attacker does not need a user account or password. Note that simply browsing the site or accessing standard features does not trigger this; the attacker must intentionally send a file specifically designed to act as a malicious backdoor.

Is my organization at risk from CVE-2025-15228?

Halo Surface Signal notes that BPMFlowWebkit is a web-based component frequently deployed as an internet-facing service to support remote access. If your installation of this technology is reachable from the public internet, it faces a higher likelihood of being targeted by unauthorized remote actors compared to systems restricted to internal-only networks.

What are the first steps to address this issue?

Start by performing a comprehensive inventory to locate all instances of BPMFlowWebkit within your infrastructure. Once identified, evaluate which systems are accessible from external networks and determine the business criticality of those assets. This data will allow you to prioritize remediation efforts and coordinate with the appropriate teams to manage the risk.

References