Medium severity6.1NVD Advisory· Published Jun 3, 2025· Updated Jun 17, 2026
CVE-2025-43924
CVE-2025-43924
Description
Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (for /fp/admin/settings/loginpage) and the rootserviceurl parameter in FriendsController (for /fp/admin/settings/friends), entered by an admin, allow stored XSS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: = 7.6.1
Patches
Vulnerability mechanics
References
2- www.unicomsi.com/security-advisory/nvdVendor Advisory
- www.unicomsi.com/products/focal-point/nvdProduct
News mentions
0No linked articles in our index yet.