CVE-2020-28136

Severity
8.8HIGH
EPSS
2.4%
top 14.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17
Latest updateMay 24

Description

An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-mfr8-h382-jvv4: An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 12022-05-24
CVEList
CVE-2020-28136: An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 12020-11-17
CVE-2020-28136 (HIGH CVSS 8.8) | An Arbitrary File Upload is discove | cvebase.io