CVE-2025-5182

A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability affects unknown code of the component Listing Handler. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 1.0.2 is able to address this issue. It is recommended to upgrade the affected component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:summerpearlgroup:vacation_rental_management_platform:*:*:*:*:*:*:*:*

History

03 Jun 2025, 15:45

Type Values Removed Values Added
CWE CWE-639
References () https://vuldb.com/?ctiid.310270 - () https://vuldb.com/?ctiid.310270 - Permissions Required, VDB Entry
References () https://www.youtube.com/watch?v=0wwuatTa6sU - () https://www.youtube.com/watch?v=0wwuatTa6sU - Exploit
References () https://summerpearlgroup.gr/spgpm/releases - () https://summerpearlgroup.gr/spgpm/releases - Release Notes
References () https://vuldb.com/?id.310270 - () https://vuldb.com/?id.310270 - Third Party Advisory, VDB Entry
References () https://github.com/Stolichnayer/Summer-Pearl-Group-IDOR-XSS - () https://github.com/Stolichnayer/Summer-Pearl-Group-IDOR-XSS - Not Applicable
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:summerpearlgroup:vacation_rental_management_platform:*:*:*:*:*:*:*:*
First Time Summerpearlgroup
Summerpearlgroup vacation Rental Management Platform

28 May 2025, 18:15

Type Values Removed Values Added
CWE CWE-285
CWE-639
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : unknown

26 May 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-26 11:15

Updated : 2025-06-03 15:45


NVD link : CVE-2025-5182

Mitre link : CVE-2025-5182


JSON object : View

Products Affected

summerpearlgroup

  • vacation_rental_management_platform
CWE
CWE-639

Authorization Bypass Through User-Controlled Key