Description
A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The patch is identified as d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. It is best practice to apply a patch to resolve this issue.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

The flaw is located in the MenpiaodingdanController.java component of the Tourism‑Management‑System. By manipulating the ID, an attacker can bypass the system’s authorization checks and gain access to or modify resources that should be forbidden. The vulnerability aligns with CWE‑285 and CWE‑639, indicating that the authorization logic is incorrectly implemented. This weakness enables unauthorized users to retrieve or alter sensitive data, compromising confidentiality and integrity of the application’s managed records.

Affected Systems

The issue affects all deployed instances of jaychouchannel:Tourism‑Management‑System that have not applied the patch identified by commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. Version information is unavailable because the project follows a rolling‑release model, so any build prior to that commit is considered vulnerable.

Risk and Exploitability

The CVSS score is 5.3. The EPSS score is less than 1 %, indicating a very low but non‑zero exploitation probability. The exploit has been publicly disclosed and can be performed remotely by sending crafted requests with a malicious ID value. There is no indication of large‑scale exploitation yet, but the vulnerability remains actionable and requires prompt remediation to prevent unauthorized access.

Generated by OpenCVE AI on September 15, 2026 at 16:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch identified by commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86, which corrects the ID handling logic the patched application to all environments so that the authorization bypass path is eliminated
  • Implement strict input validation for the ID parameter and enforce role‑based access controls to guarantee that only users with the proper permissions can set or alter the ID argument
  • Review all other CRUD endpoints in the application for similar authorization checks and ensure they enforce proper permissions before proceeding

Generated by OpenCVE AI on September 15, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The patch is identified as d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. It is best practice to apply a patch to resolve this issue.
Title jaychouchannel Tourism-Management-System CRUD MenpiaodingdanController.java authorization
First Time appeared Jaychouchannel
Jaychouchannel tourism-management-system
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
Vendors & Products Jaychouchannel
Jaychouchannel tourism-management-system
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Jaychouchannel Tourism-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T17:24:39.245Z

Reserved: 2026-09-12T10:54:54.566Z

Link: CVE-2026-90521

cve-icon Vulnrichment

Updated: 2026-09-14T17:24:32.290Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T13:16:28.927

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90521

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key