"value":"File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files via /system/application/libs/js/tinymce/plugins/filemanager/dialog.php and /system/application/libs/js/tinymce/plugins/filemanager/upload.php."
"value":"Vulnerabilidad de carga de archivos en la reserva de gira de asith-eranga ISIC a trav\u00e9s de la versi\u00f3n publicada el 13 de febrero de 2018, permite a los atacantes cargar archivos arbitrarios a trav\u00e9s de /system/application/libs/js/tinymce/plugins/filemanager/dialog.php and /system/application/libs/js/tinymce/plugins/filemanager/upload.php. "