CVE-2025-32220

Missing Authorization vulnerability in Dimitri Grassi Salon booking system allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Salon booking system: from n/a through 10.10.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:salonbookingsystem:salon_booking_system:*:*:*:*:*:wordpress:*:*

History

11 Apr 2025, 13:07

Type Values Removed Values Added
First Time Salonbookingsystem salon Booking System
Salonbookingsystem
CPE cpe:2.3:a:salonbookingsystem:salon_booking_system:*:*:*:*:*:wordpress:*:*
References () https://patchstack.com/database/wordpress/plugin/salon-booking-system/vulnerability/wordpress-salon-booking-system-plugin-10-10-7-broken-access-control-vulnerability?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/salon-booking-system/vulnerability/wordpress-salon-booking-system-plugin-10-10-7-broken-access-control-vulnerability?_s_id=cve - Third Party Advisory

07 Apr 2025, 14:18

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de falta de autorización en Dimitri Grassi Salon booking system permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta al sistema de reservas del Salón: desde n/d hasta la versión 10.10.7.

04 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-04 16:15

Updated : 2025-04-11 13:07


NVD link : CVE-2025-32220

Mitre link : CVE-2025-32220

CVE.ORG link : CVE-2025-32220


JSON object : View

Products Affected

salonbookingsystem

  • salon_booking_system
CWE
CWE-862

Missing Authorization