A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknown function of the file /dashboard/home/profile of the component User Information Module. Performing a manipulation of the argument fullname results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
| Link | Resource |
|---|---|
| https://github.com/4m3rr0r/PoCVulDb/issues/12 | Exploit Issue Tracking Mitigation Vendor Advisory |
| https://vuldb.com/?ctiid.343360 | Permissions Required VDB Entry |
| https://vuldb.com/?id.343360 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.740738 | Third Party Advisory VDB Entry |
Configurations
History
19 Feb 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:bdtask:bhojon:*:*:*:*:*:*:*:* | |
| References | () https://github.com/4m3rr0r/PoCVulDb/issues/12 - Exploit, Issue Tracking, Mitigation, Vendor Advisory | |
| References | () https://vuldb.com/?ctiid.343360 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.343360 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.740738 - Third Party Advisory, VDB Entry | |
| First Time |
Bdtask
Bdtask bhojon |
29 Jan 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-29 18:16
Updated : 2026-02-19 21:17
NVD link : CVE-2026-1598
Mitre link : CVE-2026-1598
CVE.ORG link : CVE-2026-1598
JSON object : View
Products Affected
bdtask
- bhojon
