CVE-2026-90522: jaychouchannel Tourism-Management-System Password Recovery UsersController.java resetPass password recovery
A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
jaychouchannel Tourism-Management-System (Password Recovery / UsersController.java resetPass)to a version that resolves this vulnerability.Patch 9cb6215ac871f99a90cde763cf003e95ff282283
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue can be initiated remotely and requires no privileges or user interaction, according to the supplied severity vector. Systems exposing the affected password-recovery functionality are therefore the relevant attack surface.
Is a public exploit available?
Yes. The exploit has been publicly disclosed and may be used.
Which releases are affected or fixed?
The affected code is reported through commit d984d172dceca907f8b447efbdb06dc233f7938d. Because the product uses continuous delivery with rolling releases, no affected or fixed version numbers are available; the identified patch is 9cb6215ac871f99a90cde763cf003e95ff282283.
What should teams do if they cannot immediately confirm a version number?
Compare the deployed source or build provenance with the identified patch and apply patch 9cb6215ac871f99a90cde763cf003e95ff282283. Version-based verification is not available for this issue.