CVE-2025-62319Disclosure(hcltech / unica)

LOWCVSS 9.8 · CRITICAL

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition evaluates to true or false. This allows an attacker to inject arbitrary SQL into backend configuration queries executed within the application.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unica
  • unica_audience_central

Threat summary

  • 6 mentions across 1 observed day

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • 6 total mentions across 1 day

Affected systems

Vendors
Products
unicaunica_audience_central

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-03-16: 6Technical Details · 2026-03-16: 603-16
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets6 URLs
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-62319 Boolean-Based SQL Injection https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-62319

    Post summary

    The entry identifies CVE-2025-62319 as a Boolean‑based SQL injection vulnerability, linking to a vulnerability database, but offers no PoC, exploitation details, or remediation information.

    0000086
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-62319 - Boolean-Based SQL Injection in Multiple Unica Components Intel Report: https://ift.tt/vnBCqZp

    Post summary

    The alert announces CVE‑2025‑62319 as a boolean‑based SQL injection affecting multiple Unica components, with an associated Intel Report link.

    00000120
    335 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-62319 - Critical Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Inste... https://www.thehackerwire.com/vulnerability/CVE-2025-62319/ https://t.co/I8WdRaFYAX

    Post summary

    The text announces CVE‑2025‑62319 as a critical Boolean‑based SQL injection vulnerability, providing a technical description but no evidence of active exploitation, PoC, or patches.

    00000130
    136 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-62319: CRITICAL] Boolean-Based SQL Injection uses Boolean conditions to manipulate SQL queries by injecting TRUE/FALSE values. Attackers can execute arbitrary SQL queries through input fields, expl...#cve,CVE-2025-62319,#cybersecurity https://cvefind.com/CVE-2025-62319

    Post summary

    The post announces the CRITICAL CVE‑2025‑62319, detailing a boolean‑based SQL injection that allows arbitrary SQL query execution. No proof‑of‑concept, exploitation evidence, or mitigation is provided.

    0000077
    601 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-62319 Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into applicatio… https://www.cve.org/CVERecord?id=CVE-2025-62319

    Post summary

    The text only gives a generic description of CVE‑2025‑62319 as a Boolean‑based SQL injection with no evidence of PoC, exploit, patch, or active use.

    0000088
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-62319: Boolean-Based SQL Injection in M... HCL Unica's blind SQLi in backend config queries means attackers can extract entire databases without triggering error ... https://zerodaysignal.com/vulnerability/CVE-2025-62319 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a Boolean-based blind SQL injection vulnerability (CVE-2025-62319) in HCL Unica, noting potential for data extraction but offering no PoC, exploit code, or patch details.

    00000128
    151 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apphcltechunica---
Apphcltechunica_audience_central---

Explore more