CVE-2022-44401 Online Tours & Travels Management System v10 contains an arbitrary file upload vulnerability via /tour/admin/filephp authentication complexity vector not available not available not available confidentiality integrity availability not available not available not available CVSS Score: not available References githubcom/lcg-