VYPR

Tourism Management System

by Phpgurukul

CVEs (8)

  • CVE-2025-13247HigNov 16, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in PHPGurukul Tourism Management System 1.0. The affected element is an unknown function of the file /admin/user-bookings.php. The manipulation of the argument uid results in sql injection. It is possible to launch the attack remotely. The…

  • CVE-2024-9816Oct 10, 2024
    risk 0.00cvss epss 0.01

    A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be…

  • CVE-2024-9815Oct 10, 2024
    risk 0.00cvss epss 0.01

    A vulnerability has been found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/create-package.php. The manipulation of the argument packageimage leads to unrestricted upload. The…

  • CVE-2024-41333Aug 6, 2024
    risk 0.00cvss epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the uname parameter.

  • CVE-2024-32256Apr 16, 2024
    risk 0.00cvss epss 0.01

    Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.

  • CVE-2024-32254Apr 16, 2024
    risk 0.00cvss epss 0.01

    Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image.

  • CVE-2024-1822Feb 23, 2024
    risk 0.00cvss epss 0.00

    A vulnerability classified as problematic has been found in PHPGurukul Tourism Management System 1.0. Affected is an unknown function of the file user-bookings.php. The manipulation of the argument Full Name leads to cross site scripting. It is possible to launch the attack…

  • CVE-2020-28136Nov 17, 2020
    risk 0.00cvss epss 0.03

    An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.