CVE-2020-28136: Phpgurukul Tourism Management System
High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.
An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.
Affected products
- Phpgurukul Tourism Management System: version 1.0 only
Published 2020-11-17. Last modified 2026-06-17.