CVE-2025-31887

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 1, 2025
CWE ID 862

Summary

CVE-2025-31887 is a new vulnerability affecting zookatron MyBookProgress by Stormhill Media. This issue involves a Missing Authorization flaw, which allows unauthorized access if the access control security levels are incorrectly configured. The vulnerability affects MyBookProgress versions from n/a through 1.0.8, putting potentially numerous installations at risk. Exploitation of this weakness could result in significant data compromise or unauthorized system access. Organizations using this software are urged to apply the necessary updates or patches as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share