CVE-2020-28136: Phpgurukul Tourism Management System

High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.

An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.

Affected products

  • Phpgurukul Tourism Management System: version 1.0 only

Published 2020-11-17. Last modified 2026-06-17.