Vulnerabilities > CVE-2025-5182 - Authorization Bypass Through User-Controlled Key vulnerability in Summerpearlgroup Vacation Rental Management Platform

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
summerpearlgroup
CWE-639

Summary

A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability affects unknown code of the component Listing Handler. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 1.0.2 is able to address this issue. It is recommended to upgrade the affected component.

Vulnerable Configurations

Part Description Count
Application
Summerpearlgroup
1