CVE-2025-57642

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
10/09/2025
Last modified:
17/10/2025

Description

A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sohamjuhin:tourism_management_system:2.0:*:*:*:*:*:*:*