在 jaychouchannel 旅游管理系统(Tourism-Management-System)中,版本至 8122bf020d91199eddfff3ee02d1632a70a9a132 发现了一个漏洞。该问题影响了 CRUD 组件中 MenpiaodingdanController.java 文件的某些未明确指出的处理逻辑。通过操纵参数 ID,攻击者可以实现授权绕过(Authorization Bypass)。该攻击可以在远程发起,且该漏洞的利用方式已经公开,可能被实际利用。由于该产品采用滚动发布模式以实现
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jaychouchannel | Tourism-Management-System | 8122bf020d91199eddfff3ee02d1632a70a9a132 |
cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90522 | 7.3 HIGH | jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass |
| CVE-2026-90523 | 7.3 HIGH | jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privi |
| CVE-2026-90524 | 7.3 HIGH | jaychouchannel Tourism-Management-System Update Endpoint missing authentication |
| CVE-2026-90520 | 6.3 MEDIUM | jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationIntercepto |
No comments yet