Home

Description

An issue was discovered in ReportController in Unicom Focal Point 7.6.1. A user who has administrative privilege in Focal Point can perform SQL injection via the image parameter during a delete report image operation.

PUBLISHED Reserved 2025-04-19 | Published 2025-06-03 | Updated 2025-06-04 | Assigner mitre

References

www.unicomsi.com/products/focal-point/

www.unicomsi.com/security-advisory/

cve.org (CVE-2025-43923)

nvd.nist.gov (CVE-2025-43923)

Download JSON