Impact
A flaw in the AuthorizationInterceptor.java component of the Tourism-Management-System allows an attacker to bypass normal authorization checks. The weakness permits an attacker to gain privileges beyond those assigned to the user, potentially accessing sensitive data or performing privileged actions. The vulnerability is considered moderate with a CVSS score of 5.3 and has been publicly disclosed, meaning exploitation code is available.
Affected Systems
The affected product is the Tourism-Management-System released by Jaychouchannel. All versions up to the commit hash 84d8ec384f669df3985293dab293bb7b477efa64 are vulnerable. The project follows a rolling release model, so no fixed version list exists; the patch with hash d984d172dceca907f8b447efbdb06dc233f7938d addresses the issue.
Risk and Exploitability
The CVSS of 5.3 indicates moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation, but public disclosure means exploitation code is available. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; an attacker could target the system through its web interface or APIs to exploit the improper authorization logic, enabling unauthorized actions.
OpenCVE Enrichment