CVE-2025-5182

A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as critical. This vulnerability affects unknown code of the component Listing Handler. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 1.0.2 is able to address this issue. It is recommended to upgrade the affected component.
Configurations

Configuration 1 (hide)

cpe:2.3:a:summerpearlgroup:vacation_rental_management_platform:*:*:*:*:*:*:*:*

History

03 Jun 2025, 15:45

Type Values Removed Values Added
CPE cpe:2.3:a:summerpearlgroup:vacation_rental_management_platform:*:*:*:*:*:*:*:*
First Time Summerpearlgroup
Summerpearlgroup vacation Rental Management Platform
References () https://github.com/Stolichnayer/Summer-Pearl-Group-IDOR-XSS - () https://github.com/Stolichnayer/Summer-Pearl-Group-IDOR-XSS - Not Applicable
References () https://summerpearlgroup.gr/spgpm/releases - () https://summerpearlgroup.gr/spgpm/releases - Release Notes
References () https://vuldb.com/?ctiid.310270 - () https://vuldb.com/?ctiid.310270 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.310270 - () https://vuldb.com/?id.310270 - Third Party Advisory, VDB Entry
References () https://www.youtube.com/watch?v=0wwuatTa6sU - () https://www.youtube.com/watch?v=0wwuatTa6sU - Exploit

28 May 2025, 18:15

Type Values Removed Values Added
References () https://github.com/Stolichnayer/Summer-Pearl-Group-IDOR-XSS - () https://github.com/Stolichnayer/Summer-Pearl-Group-IDOR-XSS -

28 May 2025, 15:01

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad en Summer Pearl Group Vacation Rental Management Platform (hasta la versión 1.0.1), clasificada como crítica. Esta vulnerabilidad afecta al código desconocido del componente Listing Handler. La manipulación permite la omisión de la autorización. El ataque puede ejecutarse en remoto. Actualizar a la versión 1.0.2 puede solucionar este problema. Se recomienda actualizar el componente afectado.

26 May 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-26 11:15

Updated : 2025-06-03 15:45


NVD link : CVE-2025-5182

Mitre link : CVE-2025-5182

CVE.ORG link : CVE-2025-5182


JSON object : View

Products Affected

summerpearlgroup

  • vacation_rental_management_platform
CWE
CWE-285

Improper Authorization

CWE-639

Authorization Bypass Through User-Controlled Key