CVE-2025-31560

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Apr 1, 2025
Updated: Apr 14, 2025
CWE ID 266

Summary

CVE-2025-31560 is a Privilege Escalation vulnerability affecting the Dimitri Grassi Salon booking system. The system contains an Incorrect Privilege Assignment issue, which allows unauthorized users to elevate their privileges. Specifically, this vulnerability exists in versions from n/a through 10.11. If exploited, this issue could potentially grant attackers access to sensitive data or functionality within the system. Users of the affected salon booking system are advised to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share