CVE-2025-9153: itsourcecode Online Tour and Travel Management System travellers.php unrestricted upload
A vulnerability was detected in itsourcecode Online Tour and Travel Management System 1.0. This vulnerability affects unknown code of the file /admin/operations/travellers.php. The manipulation of the argument photo results in unrestricted upload. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9153?
The severity of CVE-2025-9153 is critical due to the potential for remote code execution through unrestricted file upload.
How do I fix CVE-2025-9153?
To fix CVE-2025-9153, implement proper validation and restriction mechanisms for file uploads in the /admin/operations/travellers.php file.
Who is affected by CVE-2025-9153?
CVE-2025-9153 affects all installations of itsourcecode Online Tour and Travel Management System version 1.0.
What type of vulnerability is CVE-2025-9153?
CVE-2025-9153 is classified as a remote file upload vulnerability.
Can CVE-2025-9153 be exploited remotely?
Yes, CVE-2025-9153 can be exploited remotely, allowing attackers to upload malicious files without authentication.