PT-2026-90854 · Jaychouchannel · Tourism Management System

·

CVE-2026-90520

·

Published

2026-09-13

·

Updated

2026-09-20

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions jaychouchannel Tourism-Management-System versions up to 84d8ec384f669df3985293dab293bb7b477efa64
Description Improper authorization exists within the Authorization Interceptor component, specifically affecting the AuthorizationInterceptor.java file. This flaw allows a remote attacker to manipulate the system to bypass authorization controls.
Recommendations Apply patch d984d172dceca907f8b447efbdb06dc233f7938d to resolve the issue.

Exploit

Fix

Incorrect Privilege Assignment

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90520

Affected Products

Tourism Management System