CVE-2025-57642
HIGHSohamjuhin Tourism Management System - Unrestricted File Upload
Title source: ruleDescription
A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality.
Exploits (1)
Scores
CVSS v3
7.2
EPSS
0.0339
EPSS Percentile
87.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
sohamjuhin/tourism_management_system
2.0
Published
Sep 10, 2025
Tracked Since
Feb 18, 2026