Executive brief
The Tourism-Management-System is a full-featured tourism management platform built with Spring Boot and Vue.js. An improper authorization flaw in the Authorization Interceptor component allows attackers to bypass access controls remotely, potentially exposing administrative functions, user data, and booking information without proper credential validation.
Technical details
This vulnerability is an improper authorization flaw in the AuthorizationInterceptor.java component of the Tourism-Management-System. The vulnerability allows remote attackers to bypass authorization checks, likely due to missing or insufficient permission validation in the interceptor logic. The exploit can be initiated remotely without authentication requirements. The patch (commit d984d172dceca907f8b447efbdb06dc233f7938d) resolves authorization issues by removing @IgnoreAuth annotations inappropriately applied to restricted endpoints, re-enabling proper authorization checks. Applying the patched version is recommended.
Affected products
- Jaychou Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64
Timeline
- 2026-09-13: disclosed
- 2026-08-17: patched: Patch commit d984d172dceca907f8b447efbdb06dc233f7938d resolves authorization issues