vendor:
Holiday Travel Portal
by:
Sid3^effects
7.5
CVSS
HIGH
Upload Vulnerability
CWE
Product Name: Holiday Travel Portal
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
Holiday Travel Portal Upload Vulnerability
The vulnerability allows an attacker to upload arbitrary files to the Holiday Travel Portal website. This can lead to remote code execution or other malicious activities.
Mitigation:
The vendor should implement proper input validation and file handling techniques to prevent unauthorized file uploads. Users should update to the latest version of the software.