Impact
The checks, allowing remote attackers to manipulate the component. The missing authentication bypass defeats the system’s security controls, exposing the application to unauthorized modifications. The weakness is characterized by CWE-287 and CWE-306, both indicating insufficient or missing authentication safeguards. Consequently, an attacker could change system data, introduce malicious code, tourism management system, compromising confidentiality, integrity, and availability for users and administrators.
Affected Systems
The affected product is jaychouchannel Tourism-Management-System, as identified by the CNA vendor/product string. No specific version numbers can be pinpointed because the project follows a rolling‑release model, but all releases up to commit 229956e20dbd4a80eeff14535e44d3099502af09 are impacted. The discovered patch carries the hash 84d8ec384f669df3985293dab293bb7b477efa64 and addresses the authentication flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity, while the EPSS score is 0.00693 (<1%). The vulnerability is not listed in the CISA KEV catalog, yet the exploit is publicly available and can be launched remotely. Based on the description, it is inferred that attackers may not need special credentials to exploit the unprotected Update endpoint; the lack of authentication checks suggests remote exploitation is feasible without local access. Given the combination of remote impact, moderate CVSS, and public exploit code, the overall threat level warrants timely action.
OpenCVE Enrichment