A vulnerability has been found in code-projects Tourism Management System 1.0 and classified as critical. This vulnerability affects the function AddUser of the component User Registration. The manipulation of the argument username/password leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
History

Wed, 28 May 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Fabianros
Fabianros tourism Management System
CPEs cpe:2.3:a:fabianros:tourism_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Fabianros
Fabianros tourism Management System

Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 18 May 2025 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in code-projects Tourism Management System 1.0 and classified as critical. This vulnerability affects the function AddUser of the component User Registration. The manipulation of the argument username/password leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
Title code-projects Tourism Management System User Registration AddUser buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-05-18T17:31:04.154Z

Updated: 2025-05-19T15:22:12.092Z

Reserved: 2025-05-17T06:31:18.408Z

Link: CVE-2025-4889

cve-icon Vulnrichment

Updated: 2025-05-19T15:18:19.468Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-18T18:15:17.873

Modified: 2025-05-28T15:30:05.053

Link: CVE-2025-4889

cve-icon Redhat

No data.