Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-90522

Опубликовано: 13 сент. 2026
Источник: nvd
CVSS3: 7.3
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.

EPSS

Процентиль: 42%
0.005
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 7.3
github
8 дней назад

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.

EPSS

Процентиль: 42%
0.005
Низкий

7.3 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-640