Cross-Site Scripting Vulnerability in Course Booking Platform by André Martin
CVE-2025-58887
6.5MEDIUM
What is CVE-2025-58887?
A stored Cross-Site Scripting (XSS) vulnerability exists in the Course Booking Platform developed by André Martin. This flaw allows attackers to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, and unauthorized actions being performed on behalf of the victim. The vulnerability affects the Course Booking Platform versions up to 1.0.0, making it crucial for users to implement security measures to mitigate the risk of cross-site scripting attacks.
Affected Version(s)
Course Booking Platform <= 1.0.0