A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality.
History

Mon, 22 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Sep 2025 17:00:00 +0000

Type Values Removed Values Added
Description A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-09-22T15:51:04.077Z

Reserved: 2025-08-17T00:00:00.000Z

Link: CVE-2025-57642

cve-icon Vulnrichment

Updated: 2025-09-22T15:50:35.300Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-10T17:15:33.700

Modified: 2025-09-22T16:15:45.493

Link: CVE-2025-57642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.