Description
A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Weak Password Reset
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the resetPass function of UsersController.java within the Password Recovery component and allows an attacker to manipulate the password reset flow to set a weak or predictable password. This can lead to account compromise without proper validation and is classified as CWE-640.

Affected Systems

The vulnerability affects the jaychouchannel Tourism-Management-System open-source project hosted listed beyond the commit d984d172dceca907f8b447efbdb06dc233f7938d. The patch that addresses the issue is committed as 9cb6215ac871f99a90cde763cf003e95ff282283.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium to high severity. The EPSS score of < 1% indicates a low probability of exploitation, yet the issue has been publicly disclosed and is known to be exploitable. The attack vector is remote; the CVE description suggests that a web request could trigger the defective password reset, but this is inferred. Continuous delivery with rolling releases means no version is verified to be fixed, and the vulnerability is not listed in the CISA KEV catalog. Effective mitigation hinges on applying the supplied patch or implementing equivalent controls over the password reset flow.

Generated by OpenCVE AI on September 15, 2026 at 17:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch commit 9cb6215ac871f99a90cde763cf003e95ff282283 to the project repository.
  • Rigorously enforce strong password, and optionally disable unverified reset requests to prevent exploitation.
  • Audit all authentication endpoints for consistent input validation and consider deploying application‑layer security controls to block suspicious reset attempts.

Generated by OpenCVE AI on September 15, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.
Title jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass password recovery
First Time appeared Jaychouchannel
Jaychouchannel tourism-management-system
Weaknesses CWE-640
CPEs cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:*
Vendors & Products Jaychouchannel
Jaychouchannel tourism-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Jaychouchannel Tourism-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:08:37.583Z

Reserved: 2026-09-12T10:54:58.130Z

Link: CVE-2026-90522

cve-icon Vulnrichment

Updated: 2026-09-16T14:08:32.880Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T13:16:29.090

Modified: 2026-09-16T15:18:28.383

Link: CVE-2026-90522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password