CVE-2025-43923

An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via the image parameter during a delete report image operation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:unicomsi:focal_point:7.6.1:*:*:*:*:*:*:*

History

09 Jun 2025, 18:05

Type Values Removed Values Added
First Time Unicomsi focal Point
Unicomsi
CPE cpe:2.3:a:unicomsi:focal_point:7.6.1:*:*:*:*:*:*:*
References () https://www.unicomsi.com/products/focal-point/ - () https://www.unicomsi.com/products/focal-point/ - Product
References () https://www.unicomsi.com/security-advisory/ - () https://www.unicomsi.com/security-advisory/ - Vendor Advisory

04 Jun 2025, 21:15

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

04 Jun 2025, 14:54

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema en ReportController en Unicom Focal Point 7.6.1. Un usuario con privilegios administrativos en Focal Point puede realizar una inyección SQL mediante el parámetro de imagen durante la eliminación de una imagen de informe.

03 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 15:15

Updated : 2025-06-09 18:05


NVD link : CVE-2025-43923

Mitre link : CVE-2025-43923

CVE.ORG link : CVE-2025-43923


JSON object : View

Products Affected

unicomsi

  • focal_point
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')