CVE-2025-67954Exposure of Sensitive System Information to an Unauthorized Control Sphere in Grassi Salon Booking System

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 86.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 22

Description

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-hhmh-3f46-5wj7: Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system a2026-01-22
CVEList
WordPress Salon booking system plugin <= 10.30.3 - Sensitive Data Exposure vulnerability2026-01-22

🕵️Threat Intelligence

1
Wiz
CVE-2025-67954 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-67954 — MEDIUM severity | cvebase