PatchSiren

jaychouchannel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM jaychouchannel CVE published 2026-09-07

CVE-2026-86284

A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. The vulnerability affects the function getOption of the file travel/src/main/java/com/controller/CommonController.java, allowing for information disclosure through manipulation of the tableName/columnName arguments. The attack may be initiated remotely, and the exploit has [truncated]

MEDIUM jaychouchannel CVE published 2026-09-07

CVE-2026-86282

A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. A manipulation of the argument table/column/xColumn/yColumn can lead to sql injection. The attack can be launched remotely. This product does not use versioning. A patch is called d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86 and should be applied to remediate this issue.