CVE-2025-32253
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-32253 represents a Missing Authorization vulnerability discovered in the ComMotion Course Booking System. This issue permits unauthorized access to functionality that is not adequately restricted by Access Control Lists (ACLs). The vulnerability affects ComMotion Course Booking Systems from an unknown version up to 6.0.5. Unapproved users may exploit this flaw to gain unauthorized access and potentially disrupt system operations or steal sensitive data. It is recommended that users of the affected systems urgently install patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.