CVE-2025-56699
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
16/10/2025
Last modified:
15/04/2026
Description
SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary SQL commands via the sender parameter.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM



