📦

online_tours_and_travels

Vendor: projectworlds

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 0.35% Exploit Prob.
Latest CVE CVE-2025-11103 Sep 28

Security Vulnerability Index

Page 1 / 1
2.0 CVSS

A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

EPSS: 0.35%