Impact
A flaw in the User Register endpoint causes improper privilege management. The flaw originates from insufficient validation of the UsersEntity argument in UsersController.java, enabling an attacker to set privilege levels that should not be granted. This vulnerability is related to CWE-266 and CWE-269 and allows unauthorized users to gain elevated privileges within the application. Based on the description, it is inferred that such privilege controls.
Affected Systems
The affected product is jaychouchannel Tourism-Management-System, particularly the User Register endpoint implemented in UsersController.java. Because the project does not specify version numbers, all releases up to the patch commit 84d8ec384f669df3985293dab293bb7b477efa64 are considered vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. The EPSS score is below 1%, indicating a low but non‑zero probability of exploitation. The exploit is described as publicly available and can be triggered remotely. The lack of a KEV listing does not eliminate the need for remediation, as the identified flaw permits direct privilege escalation that an attacker with internet access could exploit. The attack requires only the ability to send a crafted UsersEntity payload to the registration endpoint, making it a feasible remote attack vector.
OpenCVE Enrichment