CVE-2026-90522
A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.50%
- CWE
- CWE-640
- Published
- 2026-09-13
- Last modified
- 2026-09-16
Affected products
- jaychouchannel Tourism-Management-System
Weakness type
Related vulnerabilities
- CVE-2023-7028 — Weak Password Recovery Mechanism for Forgotten Password in GitLab
- CVE-2025-6216 — Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability
- CVE-2025-47646 — WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
- CVE-2026-18963 — Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2024-8878 — Unauthenticated Password Reset
- CVE-2023-30466 — Authentication Bypass Vulnerability in Milesight Network Video Recorder (NVR)
- CVE-2022-3485 — Weak Password Recovery in ifm moneo appliance
- CVE-2024-11350 — AdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account Takeover