在 jaychouchannel 的 Tourism-Management-System(旅游管理系统)中(版本标识为 229956e20dbd4a80eeff14535e44d3099502af09 及之前)发现了一个安全缺陷。受影响的组件是 Update Endpoint 中一个未知功能。对该组件进行特定操作会导致认证缺失(missing authentication)。该漏洞可被远程利用,且利用代码/利用方法已公开,可被攻击者用于发起攻击。 该产品采用滚动发布(rolling release)模型,持续提供更
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jaychouchannel | Tourism-Management-System | 229956e20dbd4a80eeff14535e44d3099502af09 |
cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90522 | 7.3 HIGH | jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass |
| CVE-2026-90523 | 7.3 HIGH | jaychouchannel Tourism-Management-System User Register Endpoint UsersController.java privi |
| CVE-2026-90520 | 6.3 MEDIUM | jaychouchannel Tourism-Management-System Authorization Interceptor AuthorizationIntercepto |
| CVE-2026-90521 | 6.3 MEDIUM | jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization |
No comments yet