CVE-2026-90522

Source
https://cve.org/CVERecord?id=CVE-2026-90522
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90522.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90522
Published
2026-09-13T13:00:16Z
Modified
2026-10-08T02:52:21Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass password recovery
Details

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-640"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90522.json"
}
References

Affected packages

Git / github.com/jaychouchannel/tourism-management-system

Affected ranges

Type
GIT
Repo
https://github.com/jaychouchannel/tourism-management-system
Events

Affected versions

Other
d984d172dceca907f8b447efbdb06dc233f7938d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90522.json"