peter bassill · operator
$ cve CVE-2025-57642 JSON

CVE-2025-57642 EXPLOIT

7.2
HIGH · CVSS 3.1 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS1.59% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2025-09-10
Last modified2026-06-17

Affected (1)

VendorProduct
sohamjuhintourism management system

Public exploits

SourceTitleDate
exploit-dbTourism Management System 2.0 - Arbitrary Shell Upload2025-09-16

References

→ the Explorer  ·  watch your stack  ·  NVD