PT-2025-4699 · Unknown · Commotion Course Booking System

Lvt-Tholv2K

·

Published

2025-01-15

·

Updated

2026-03-07

·

CVE-2025-22785

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions ComMotion Course Booking System versions prior to 6.0.5
Description The issue is related to the improper neutralization of special elements used in an SQL command, allowing SQL injection. This enables unauthorized access to the system.
Recommendations For versions prior to 6.0.5, update to a version that includes the fix for this issue to prevent SQL injection attacks. As a temporary workaround, consider restricting access to sensitive database queries until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-22785

Affected Products

Commotion Course Booking System