PT-2025-23621 · Unicom · Unicom Focal Point

·

CVE-2025-43923

·

Published

2025-06-03

·

Updated

2025-06-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Unicom Focal Point version 7.6.1
Description An issue was discovered in ReportController, allowing a user with administrative privilege to perform SQL injection via the image parameter during a delete report image operation.
Recommendations For Unicom Focal Point version 7.6.1, consider restricting access to the delete report image operation to prevent potential SQL injection attacks until a patch is available. As a temporary workaround, limit the privileges of users who can perform this operation to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-43923

Affected Products

Unicom Focal Point