vendor:
Tourism Management System
by:
Ankita Pal & Saurav Shukla
9.8
CVSS
CRITICAL
Arbitrary File Upload
434
CWE
Product Name: Tourism Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:phpgurukul:tourism_management_system:1.0
Platforms Tested: Windows 10 + xampp v3.2.4
2020
Tourism Management System 1.0 – Arbitrary File Upload
The Tourism Management System 1.0 allows arbitrary file upload, which can lead to remote code execution.
Mitigation:
The vendor should implement proper input validation and file type checking to prevent arbitrary file uploads.