Projectworlds Online Tours and Travels Unrestricted File Upload Vulnerability

Vulnerability

A file upload vulnerability has been identified in Projectworlds Online Tours and Travels version 1.0, specifically in the admin/change-image.php file. This vulnerability allows for unrestricted file uploads through the packageimage parameter, enabling attackers to upload malicious files, such as web shells, which could lead to remote code execution. The vulnerability can be exploited remotely, but requires authentication as an administrator.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which could be executed on the server, potentially leading to a complete system compromise.

Reproduction

To reproduce this vulnerability, log in as an administrator and navigate to the admin/change-image.php page. Upload a file through the packageimage parameter without any restrictions on file type or content. The uploaded file can then be executed on the server.

Remediation

It is recommended to implement strict file type validation, validate file content, rename uploaded files, store files outside the web root, limit file size, and use secure permissions.

Added: Sep 28, 2025, 11:18 AM
Updated: Sep 28, 2025, 11:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.1
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.