CVE-2025-5182 Information
May 27, 2025
cve
Description
A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability affects unknown code of the component Listing Handler. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 1.0.2 is able to address this issue. It is recommended to upgrade the affected component.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Reference
https://github.com/Stolichnayer/Summer-Pearl-Group-IDOR-XSS https://summerpearlgroup.gr/spgpm/releases https://vuldb.com/?ctiid.310270 https://vuldb.com/?id.310270 https://www.youtube.com/watch?v=0wwuatTa6sU
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
4.3
Share on: