CVE-2025-63562: Summerpearlgroup Vacation Rental Management Platform

Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., owner or resource id).

Affected products

  • Summerpearlgroup Vacation Rental Management Platform: before 1.0.2 (fixed in 1.0.2)

Published 2025-10-31. Last modified 2026-06-17.