Impact
The flaw resides in the resetPass function of UsersController.java within the Password Recovery component and allows an attacker to manipulate the password reset flow to set a weak or predictable password. This can lead to account compromise without proper validation and is classified as CWE-640.
Affected Systems
The vulnerability affects the jaychouchannel Tourism-Management-System open-source project hosted listed beyond the commit d984d172dceca907f8b447efbdb06dc233f7938d. The patch that addresses the issue is committed as 9cb6215ac871f99a90cde763cf003e95ff282283.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium to high severity. The EPSS score of < 1% indicates a low probability of exploitation, yet the issue has been publicly disclosed and is known to be exploitable. The attack vector is remote; the CVE description suggests that a web request could trigger the defective password reset, but this is inferred. Continuous delivery with rolling releases means no version is verified to be fixed, and the vulnerability is not listed in the CISA KEV catalog. Effective mitigation hinges on applying the supplied patch or implementing equivalent controls over the password reset flow.
OpenCVE Enrichment