CVE-2020-28136: Malicious File Upload
Published Nov 17, 2020
·Updated
An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.
Affected Software
2 affected components
Phpgurukul Tourism Management System=1.0
Tourism Management System Project Tourism Management System=1.0
Event History
Nov 17, 2020
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
Description
Frequently Asked Questions
1
What is CVE-2020-28136?
CVE-2020-28136 is an Arbitrary File Upload vulnerability in SourceCodester Tourism Management System 1.0 that allows remote code execution via the vulnerable page admin/create-package.php.
2
How severe is CVE-2020-28136?
The severity of CVE-2020-28136 is rated as high with a CVSS score of 8.8.
3
Which software versions are affected by CVE-2020-28136?
Versions 1.0 of Tourism Management System Project and Phpgurukul Tourism Management System are affected by CVE-2020-28136.