CVE-2026-10172 Details
Description
A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
A remote code execution vulnerability exists in Bdtask Multi-Store Inventory Management System version 1.0. The issue arises in the module upload feature within the file 'application/modules/dashboard/controllers/Module.php'. The vulnerability allows authenticated admin users to upload ZIP files, which are then extracted into the 'application/modules/' directory. When the 'Add Module' view is accessed, the application executes an included PHP file from the uploaded ZIP without proper validation, enabling the execution of arbitrary PHP code on the server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 31, 2026CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kevin57545/CVE/blob/main/bdtask-multi-store-rce.md | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-10172 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/819418 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/367429 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/367429/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bdtask Multi-Store Inventory Management System | 1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 31, 2026 | New CVE Received | [email protected] |
Volerion