PT-2026-90860 · Jaychouchannel · Tourism Management System

·

CVE-2026-90523

·

Published

2026-09-13

·

Updated

2026-09-14

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions jaychouchannel Tourism-Management-System versions up to 229956e20dbd4a80eeff14535e44d3099502af09
Description Improper privilege management exists in the User Register Endpoint within the file travel/src/main/java/com/controller/UsersController.java. A remote attacker can manipulate the UsersEntity argument to gain unauthorized privileges.
Recommendations Apply patch 84d8ec384f669df3985293dab293bb7b477efa64 to resolve this issue.

Exploit

Fix

Improper Privilege Management

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90523

Affected Products

Tourism Management System