在 jaychouchannel 旅游管理系统(版本 up to 84d8ec384f669df3985293dab293bb7b477efa64)中发现了一个漏洞。该漏洞位于组件“授权拦截器”中的文件 AuthorizationInterceptor.java 的未知代码处。该缺陷导致授权机制不当。攻击者可以通过远程发起攻击。此漏洞的利用方式已公开披露,可能已被利用。由于该产品采用滚动发布模式以实现持续交付,因此没有可用的受影响版本或更新版本的详细信息。补丁的标识符为 d984d172dceca907f8b447
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jaychouchannel | Tourism-Management-System | 84d8ec384f669df3985293dab293bb7b477efa64 |
cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90522 | 7.3 HIGH | jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass |
| CVE-2026-90523 | 7.3 HIGH | jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privi |
| CVE-2026-90524 | 7.3 HIGH | jaychouchannel Tourism-Management-System Update Endpoint missing authentication |
| CVE-2026-90521 | 6.3 MEDIUM | jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization |
No comments yet