CVE-2024-32256
HIGHPhpgurukul Tourism Management System 2.0 - Unrestricted Upload of File with Dangerous Type via Change Image Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-32256. PoCs published by SoSPiro.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Tourism Management System v2.0, allowing an admin to upload a PHP file (e.g., phpinfo.php) to the server. The PoC includes a multipart/form-data request that bypasses inadequate input sanitization.
Description
Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in Tourism Management System v2.0, allowing an admin to upload a PHP file (e.g., phpinfo.php) to the server. The PoC includes a multipart/form-data request that bypasses inadequate input sanitization.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H