PT-2024-24473 · Unknown · Phpgurukul Tourism Management System
Published
2024-04-16
·
Updated
2026-02-06
·
CVE-2024-32256
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Phpgurukul Tourism Management System version 2.0
Description
The issue allows for Unrestricted Upload of File with Dangerous Type via the "/tms/admin/change-image.php" API endpoint. When updating a current package, there are no checks for what types of files are uploaded from the image.
Recommendations
For Phpgurukul Tourism Management System version 2.0, consider disabling the image upload functionality in the "/tms/admin/change-image.php" endpoint until a patch is available to prevent exploitation. Restrict access to this endpoint to minimize the risk of uploading malicious files.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpgurukul Tourism Management System