CVE-2023-1391
MEDIUMSourceCodester Online Tours & Travels Management System 1.0 - Unres...
Title source: llmDescription
A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222978 is the identifier assigned to this vulnerability.
References (3)
Core 3
Core References
Permissions Required, Third Party Advisory vdb-entry
technical-description
https://vuldb.com/?id.222978
Permissions Required, Third Party Advisory signature
permissions-required
https://vuldb.com/?ctiid.222978
Broken Link exploit
https://blog.csdn.net/Dwayne_Wade/article/details/129526901
Scores
CVSS v3
4.7
EPSS
0.0043
EPSS Percentile
62.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-434
Status
published
Products (1)
online_tours_\&_travels_management_system_project/online_tours_\&_travels_management_system
1.0
Published
Mar 14, 2023
Tracked Since
Feb 18, 2026