{ "id": "CVE-2024-32254", "sourceIdentifier": "cve@mitre.org", "published": "2024-04-16T17:15:10.987", "lastModified": "2024-04-17T12:48:31.863", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is no checks for what types of files are uploaded from the image." }, { "lang": "es", "value": "Phpgurukul Tourism Management System v2.0 es vulnerable a la carga sin restricciones de archivos con tipos peligrosos a trav\u00e9s de tms/admin/create-package.php. Al crear un nuevo paquete, no se verifica qu\u00e9 tipos de archivos se cargan desde la imagen." } ], "metrics": {}, "references": [ { "url": "https://github.com/jinhaochan/CVE-POC/blob/main/tms/POC.md", "source": "cve@mitre.org" } ] }