CVE-2025-43923

An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via the image parameter during a delete report image operation.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:unicomsi:focal_point:7.6.1:*:*:*:*:*:*:*

History

09 Jun 2025, 18:05

Type Values Removed Values Added
First Time Unicomsi focal Point
Unicomsi
References () https://www.unicomsi.com/products/focal-point/ - () https://www.unicomsi.com/products/focal-point/ - Product
References () https://www.unicomsi.com/security-advisory/ - () https://www.unicomsi.com/security-advisory/ - Vendor Advisory
CPE cpe:2.3:a:unicomsi:focal_point:7.6.1:*:*:*:*:*:*:*

03 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 15:15

Updated : 2025-06-09 18:05


NVD link : CVE-2025-43923

Mitre link : CVE-2025-43923


JSON object : View

Products Affected

unicomsi

  • focal_point
CWE

No CWE.