CVE-2025-43923

An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via the image parameter during a delete report image operation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:unicomsi:focal_point:7.6.1:*:*:*:*:*:*:*

History

09 Jun 2025, 18:05

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 15:15

Updated : 2025-06-09 18:05


NVD link : CVE-2025-43923

Mitre link : CVE-2025-43923

CVE.ORG link : CVE-2025-43923


JSON object : View

Products Affected

unicomsi

  • focal_point
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')