SQL Injection Vulnerability in ComMotion Course Booking System
CVE-2025-22785

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 January 2025

What is CVE-2025-22785?

The ComMotion Course Booking System is susceptible to an SQL Injection vulnerability that allows attackers to execute arbitrary SQL queries. This flaw permits unauthorized access to sensitive data and may lead to data manipulation or loss. Affected versions range from n/a up to 6.0.5, posing a significant risk to the integrity and security of user data. It is crucial for users of the affected versions to apply security patches and follow best practices to mitigate potential threats.

Affected Version(s)

Course Booking System <= 6.0.5

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.