VendorsSummerpearlgroupvacation_rental_management_platformall versions
Vulnerabilities

Summerpearlgroup Vacation Rental Management Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-5182
Summer Pearl Group Vacation Rental Management Platform Listing authorization
Published 2025-05-26 · Analyzed
7.5EPSS 0.004
CVE-2025-63561
Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where an attacker that opens and maintains many slow or partially-completed HTTP connections can exhaust the server’s connection pool and worker capacity, preventing legitimate users and APIs from accessing the service.
Published 2025-10-31 · Analyzed
7.5EPSS 0.004
CVE-2025-5184
Summer Pearl Group Vacation Rental Management Platform HTTP Response Header information disclosure
Published 2025-05-26 · Analyzed
7.5EPSS 0.004
CVE-2025-63563
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.
Published 2025-10-31 · Analyzed
6.5EPSS 0.002
CVE-2025-63562
Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., owner or resource id).
Published 2025-10-31 · Analyzed
6.3EPSS 0.002
CVE-2025-5181
Summer Pearl Group Vacation Rental Management Platform updateListing cross site scripting
Published 2025-05-26 · Analyzed
5.1EPSS 0.004
CVE-2025-5183
Summer Pearl Group Vacation Rental Management Platform Header redirect
Published 2025-05-26 · Analyzed
5.1EPSS 0.003