CVE-2025-32508

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 79

Summary

CVE-2025-32508 is a Cross-Site Scripting (XSS) vulnerability affecting the ComMotion Course Booking System. The system, from an unknown version up to 6.0.7, is vulnerable to Reflected XSS due to improper neutralization of user input during web page generation. An attacker could exploit this flaw to inject malicious scripts into web pages viewed by other users, potentially stealing sensitive information or taking control of their sessions. This vulnerability poses a significant risk to users who access the Course Booking System and highlights the importance of applying the necessary patch or update to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share