Description
SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary SQL commands via the sender parameter.
References
basedigitale.com/...tions/security-asset-management/centrax/
github.com/...ulnerability-research/tree/main/CVE-2025-56699