PT-2026-90855 · Jaychouchannel · Tourism Management System

·

CVE-2026-90521

·

Published

2026-09-13

·

Updated

2026-09-14

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions jaychouchannel Tourism-Management-System versions up to 8122bf020d91199eddfff3ee02d1632a70a9a132
Description An authorization bypass exists in the CRUD component within the file MenpiaodingdanController.java. A remote attacker can exploit this by manipulating the ID argument, allowing unauthorized access to system functions.
Recommendations Apply patch d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86 to resolve this issue.

Exploit

Fix

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90521

Affected Products

Tourism Management System