Unrestricted File Upload Vulnerability in ashraf-kabir Travel Agency Software
CVE-2025-13544
Key Information:
- Vendor
Ashraf-kabir
- Status
- Vendor
- CVE Published:
- 23 November 2025
Badges
What is CVE-2025-13544?
A vulnerability has been discovered in the ashraf-kabir travel-agency software that allows for unrestricted file uploads through the /customer_register.php script. Malicious actors can exploit this weakness to upload unauthorized files remotely, potentially compromising the integrity and confidentiality of the application. The vulnerability is particularly concerning as it has been made public, inviting exploitation, and the vendor has yet to respond to disclosure attempts. Continuous delivery practices in rolling releases may obscure version details for updates, leaving systems vulnerable.
Affected Version(s)
travel-agency 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
