Description
Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged user that has access to the platform, to execute arbitrary SQL commands via the datafine parameter.
References
basedigitale.com/...tions/security-asset-management/centrax/
github.com/...ulnerability-research/tree/main/CVE-2025-56700