PT-2026-90859 · Jaychouchannel · Tourism Management System

·

CVE-2026-90522

·

Published

2026-09-13

·

Updated

2026-09-13

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions jaychouchannel Tourism-Management-System (affected versions not specified)
Description A flaw in the Password Recovery component allows for weak password recovery. This issue can be triggered remotely via the resetPass() function located in the UsersController.java file.
Recommendations Apply patch 9cb6215ac871f99a90cde763cf003e95ff282283. As a temporary workaround, restrict access to the resetPass() function until the patch is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90522

Affected Products

Tourism Management System