在 jaychouchannel 的旅游管理系统(版本截至 d984d172dceca907f8b447efbdb06dc233f7938d)中发现一个漏洞。受影响的组件是“密码恢复”模块中的 文件里的 函数。该操作会导致密码恢复机制强度较弱。攻击者可以远程发起攻击。该漏洞的利用方式已公开披露,可能会被利用。由于该产品采用持续交付和滚动发布模式,因此没有提供受影响版本或已修复版本的具体信息。补丁编号:9cb6215ac871f99a90cde763cf003e95ff282283。建议应用该补丁以修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jaychouchannel | Tourism-Management-System | d984d172dceca907f8b447efbdb06dc233f7938d |
cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90523 | 7.3 HIGH | jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privi |
| CVE-2026-90524 | 7.3 HIGH | jaychouchannel Tourism-Management-System Update Endpoint missing authentication |
| CVE-2026-90520 | 6.3 MEDIUM | jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationIntercepto |
| CVE-2026-90521 | 6.3 MEDIUM | jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization |
No comments yet