CVE-2025-57642

HIGH

Sohamjuhin Tourism Management System - Unrestricted File Upload

Title source: rule

Description

A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality.

Exploits (1)

exploitdb WRITEUP
by Debug Security · textwebappsmultiple
https://www.exploit-db.com/exploits/52433

Scores

CVSS v3 7.2
EPSS 0.0339
EPSS Percentile 87.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
sohamjuhin/tourism_management_system 2.0
Published Sep 10, 2025
Tracked Since Feb 18, 2026