Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 84d8ec384f669df3985293dab293bb7b477efa64. It is suggested to install a patch to address this issue. | |
| Title | jaychouchannel Tourism-Management-System Update Endpoint missing authentication | |
| First Time appeared |
Jaychouchannel
Jaychouchannel tourism-management-system |
|
| Weaknesses | CWE-287 CWE-306 |
|
| CPEs | cpe:2.3:a:jaychouchannel:tourism-management-system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jaychouchannel
Jaychouchannel tourism-management-system |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-13T13:30:16.020Z
Reserved: 2026-09-12T10:55:04.755Z
Link: CVE-2026-90524
No data.
No data.
No data.
OpenCVE Enrichment
No data.