Unauthenticated file upload via unchecked registration image
Published Nov 23, 2025 · Updated Dec 11, 2025
Unrestricted upload in Ashraf Kabir Travel Agency at 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3 allows remote attackers to store arbitrary files. customer_register.php passes the client-supplied c_image filename and temporary upload directly to move_uploaded_file without checking the filename, extension, MIME type, or content. The public registration form requires no existing account, and the file is written beneath customer/customer_images within the application tree.
Summary
What happened
Unrestricted upload in Ashraf Kabir Travel Agency at 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3 allows remote attackers to store arbitrary files. customer_register.php passes the client-supplied c_image filename and temporary upload directly to move_uploaded_file without checking the filename, extension, MIME type, or content. The public registration form requires no existing account, and the file is written beneath customer/customer_images within the application tree.
The record
- CVE
- CVE-2025-13544
- Published
- Nov 23, 2025
- Updated
- Dec 11, 2025
- Vendor
- Ashraf Kabir
- Product
- Travel Agency
- Classifications
- CWE-434, CWE-284, T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Nov 23, 2025CVE publishedPublication date reported by the CVE source.
- Dec 11, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Travel Agency file-upload proof of conceptproof of concept · unverified
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo