在 jaychouchannel Tourism-Management-System 中识别出一个漏洞,影响版本范围为 commit 229956e20dbd4a80eeff14535e44d3099502af09 之前的版本。受影响的组件为 “用户注册端点(User Register Endpoint)”,具体位于文件 中的一个未知函数。对 参数的不当操作会导致权限管理不当(improper privilege management)。该漏洞可被远程触发,且已存在公开的利用方式,可能被攻击者利用。由于该产品未采用
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jaychouchannel | Tourism-Management-System | 229956e20dbd4a80eeff14535e44d3099502af09 |
cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90522 | 7.3 HIGH | jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass |
| CVE-2026-90524 | 7.3 HIGH | jaychouchannel Tourism-Management-System Update Endpoint missing authentication |
| CVE-2026-90520 | 6.3 MEDIUM | jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationIntercepto |
| CVE-2026-90521 | 6.3 MEDIUM | jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization |
No comments yet