Executive brief
Tourism-Management-System is a web-based platform for managing travel businesses, including attractions, hotels, restaurants, and ticketing. A flaw in the CRUD (data modification) component allows attackers to bypass authorization checks by manipulating request parameters, potentially gaining unauthorized access to sensitive business data or making unauthorized changes to the system.
Technical details
An authorization bypass vulnerability exists in the MenpiaodingdanController.java component of Tourism-Management-System. The vulnerability is triggered by improper validation of the ID argument in CRUD operations, allowing attackers to access or modify records they should not have permission to access. The vulnerability is network-accessible and requires no authentication. The exploit is public, and a patch (commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86) is available and should be applied immediately.
Affected products
- jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132
Timeline
- 2026-09-13: disclosed: CVE-2026-90521 published
- 2026-09-13: patched: Patch available as commit d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86