Welltend Technology BPMFlowWebkit Absolute Path Traversal Vulnerability Allowing Arbitrary File Read

Vulnerability

A vulnerability allowing arbitrary file read has been identified in BPMFlowWebkit developed by Welltend Technology, affecting versions prior to 5.0.5. This vulnerability arises from absolute path traversal, enabling unauthenticated remote attackers to download arbitrary system files.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive system files, which could lead to further attacks or information disclosure.

Remediation

Users are advised to update BPMFlowWebkit to version 5.0.5 or later.

Added: Dec 29, 2025, 8:18 AM
Updated: Dec 29, 2025, 4:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
7.4
remediation
7.7
relevance
1.6
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.