Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31459 | A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. |
Fri, 03 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:projectworlds:online_tours_and_travels:1.0:*:*:*:*:*:*:* |
Mon, 29 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Projectworlds
Projectworlds online Tours And Travels |
|
| Vendors & Products |
Projectworlds
Projectworlds online Tours And Travels |
Sun, 28 Sep 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Title | Projectworlds Online Tours and Travels change-image.php unrestricted upload | |
| Weaknesses | CWE-284 CWE-434 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-29T14:10:12.531Z
Reserved: 2025-09-27T17:16:02.334Z
Link: CVE-2025-11103
Updated: 2025-09-29T14:10:04.024Z
Status : Analyzed
Published: 2025-09-28T11:15:31.940
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-11103
No data.
OpenCVE Enrichment
Updated: 2025-09-29T09:29:31Z
EUVD