Vulnerability Description
Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/update_settings.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Online Tours And Travels Management System Project | Online Tours And Travels Management System | 1.0 |
References
- https://github.com/xd201qaz/bug_report/blob/main/vendors/mayuri_k/online-tours-tExploitThird Party Advisory
- https://github.com/xd201qaz/bug_report/blob/main/vendors/mayuri_k/online-tours-tExploitThird Party Advisory
FAQ
What is CVE-2022-42142?
CVE-2022-42142 is a vulnerability with a CVSS score of 7.2 (HIGH). Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/update_settings.php.
How severe is CVE-2022-42142?
CVE-2022-42142 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-42142?
Check the references section above for vendor advisories and patch information. Affected products include: Online Tours And Travels Management System Project Online Tours And Travels Management System.