CVE-2022-41537: Online Tours & Travels Management System Project Online Tours & Travels Management System

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

Affected products

Published 2022-10-18. Last modified 2026-06-17.