HIGH
CVE-2026-90522
CVSS
7.3
Description
A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.
Weakness (CWE)
CWE-640
EPSS Score
0.5%
Probability of exploitation in next 30 days
41.8th percentile
References
https://github.com/jaychouchannel/Tourism-Management-System/
https://github.com/jaychouchannel/Tourism-Management-System/commit/9cb6215ac871f99a90cde763cf003e95ff282283
https://github.com/jaychouchannel/Tourism-Management-System/issues/13
https://vuldb.com/cve/CVE-2026-90522
https://vuldb.com/submit/912236
https://vuldb.com/vuln/403112
https://vuldb.com/vuln/403112/cti
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.