Impact
The flaw is located in the MenpiaodingdanController.java component of the Tourism‑Management‑System. By manipulating the ID, an attacker can bypass the system’s authorization checks and gain access to or modify resources that should be forbidden. The vulnerability aligns with CWE‑285 and CWE‑639, indicating that the authorization logic is incorrectly implemented. This weakness enables unauthorized users to retrieve or alter sensitive data, compromising confidentiality and integrity of the application’s managed records.
Affected Systems
The issue affects all deployed instances of jaychouchannel:Tourism‑Management‑System that have not applied the patch identified by commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. Version information is unavailable because the project follows a rolling‑release model, so any build prior to that commit is considered vulnerable.
Risk and Exploitability
The CVSS score is 5.3. The EPSS score is less than 1 %, indicating a very low but non‑zero exploitation probability. The exploit has been publicly disclosed and can be performed remotely by sending crafted requests with a malicious ID value. There is no indication of large‑scale exploitation yet, but the vulnerability remains actionable and requires prompt remediation to prevent unauthorized access.
OpenCVE Enrichment