📦 Online Tour \& Travel Management System

by Mayurik

🔍 What is Online Tour \& Travel Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-9425

HIGH CVSS 7.3 Aug 25, 2025

CVE-2025-9425 is a SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 that allows remote attackers to execute arbitrary SQL commands via the pid parameter in /enq...

CVE-2025-9155

HIGH CVSS 7.3 Aug 19, 2025

This CVE describes an SQL injection vulnerability in the Online Tour and Travel Management System 1.0. Attackers can exploit the email parameter in the forget_password.php file to execute arbitrary SQ...

CVE-2025-9154

HIGH CVSS 7.3 Aug 19, 2025

CVE-2025-9154 is an SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 that allows remote attackers to execute arbitrary SQL commands via the email parameter in /...

CVE-2025-9009

HIGH CVSS 7.3 Aug 15, 2025

This vulnerability allows remote attackers to execute SQL injection attacks against the Online Tour and Travel Management System 1.0. By manipulating the 'Name' parameter in the /admin/email_setup.php...

CVE-2025-9008

HIGH CVSS 7.3 Aug 15, 2025

This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'uname' parameter in /admin/sms_setting.php. At...

CVE-2025-8993

HIGH CVSS 7.3 Aug 15, 2025

This SQL injection vulnerability in Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through the 'from_date' parameter in /admin/expense_report.php. Attacke...

CVE-2025-8983

HIGH CVSS 7.3 Aug 14, 2025

This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'expense_for' parameter in the /admin/op...

CVE-2025-8981

HIGH CVSS 7.3 Aug 14, 2025

This SQL injection vulnerability in Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through the payment_type parameter in /admin/operations/payment.php. At...

CVE-2025-8972

HIGH CVSS 7.3 Aug 14, 2025

This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through the email parameter in the login page. Remote atta...

CVE-2025-8971

HIGH CVSS 7.3 Aug 14, 2025

This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'val-username' parameter in the /admin/operatio...

CVE-2025-8969

HIGH CVSS 7.3 Aug 14, 2025

This SQL injection vulnerability in Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through the /admin/approve_user.php endpoint. Attackers can potentially...

CVE-2025-8966

HIGH CVSS 7.3 Aug 14, 2025

This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'tname' parameter in the /admin/operations/tax....

CVE-2025-9153

MEDIUM CVSS 6.3 Aug 19, 2025

This vulnerability allows remote attackers to upload arbitrary files to the Online Tour and Travel Management System 1.0 via the photo parameter in /admin/operations/travellers.php. This can lead to s...