What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ComMotion Course Booking System course-booking-system allows SQL Injection.This issue affects Course Booking System: from n/a through <= 6.0.6.
Explanation of Vulnerability in Simple Terms
02Summary
The Course Booking System contains a SQL injection vulnerability in versions up to 6.0.6. An attacker can craft malicious input to execute arbitrary SQL queries against the database, potentially reading sensitive booking and user data. No authentication is required. The vulnerability also impacts system availability.
What an attacker can do
03Attacker Capabilities
Execute SQL queries to read or modify database records without authentication.
Potential impact on your site
04Site Impact
Attackers can steal booking data, user information, and payment details; may also disrupt service availability.
Conditions required to exploit
05Prerequisites
Network access to the vulnerable application; no login or user interaction required.
Key dates
06Disclosure timeline
January 15, 2025
CVE published
April 28, 2026
Record updated