PT-2025-23621 · Unicom · Unicom Focal Point
Ianis Bernard
·
Published
2025-06-03
·
Updated
2025-06-03
·
CVE-2025-43923
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Unicom Focal Point version 7.6.1
Description
An issue was discovered in ReportController, allowing a user with administrative privilege to perform SQL injection via the
image parameter during a delete report image operation.Recommendations
For Unicom Focal Point version 7.6.1, consider restricting access to the delete report image operation to prevent potential SQL injection attacks until a patch is available. As a temporary workaround, limit the privileges of users who can perform this operation to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unicom Focal Point