Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90521— jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization

Quick assessment

Affected
jaychouchannel Tourism-Management-System
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 jaychouchannel 旅游管理系统(Tourism-Management-System)中,版本至 8122bf020d91199eddfff3ee02d1632a70a9a132 发现了一个漏洞。该问题影响了 CRUD 组件中 MenpiaodingdanController.java 文件的某些未明确指出的处理逻辑。通过操纵参数 ID,攻击者可以实现授权绕过(Authorization Bypass)。该攻击可以在远程发起,且该漏洞的利用方式已经公开,可能被实际利用。由于该产品采用滚动发布模式以实现

CVSS 6.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90521

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The patch is identified as d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. It is best practice to apply a patch to resolve this issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
jaychouchannel Tourism-Management-System 8122bf020d91199eddfff3ee02d1632a70a9a132 cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-90521

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90521

登录查看更多情报信息。

Patches & Fixes for CVE-2026-90521 (1)

Proof of Concept for CVE-2026-90521 (1)

Other References for CVE-2026-90521 (1)

Same Patch Batch · jaychouchannel · 2026-09-13 · 5 CVEs total

CVE-2026-90522 7.3 HIGH jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass
CVE-2026-90523 7.3 HIGH jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privi
CVE-2026-90524 7.3 HIGH jaychouchannel Tourism-Management-System Update Endpoint missing authentication
CVE-2026-90520 6.3 MEDIUM jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationIntercepto

IV. Related Vulnerabilities

V. Comments for CVE-2026-90521

No comments yet


Leave a comment