CVE-2025-11103Medium· 4.7▾ SunlitA security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
online_tours_and_travels = 1.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11426Medium· 6.3A security flaw has been discovered in projectworlds Advanced Library Management System 1.0
CVE-2025-13573Medium· 6.3A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0
CVE-2025-12862Medium· 6.3A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0
CVE-2025-11347High· 7.3A vulnerability was found in code-projects Student Crud Operation up to 3.3
CVE-2025-11318High· 7.3A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0
CVE-2025-11908Medium· 6.3A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40