← Vulnerability feed

Vulnerability record · CVE-2025-62319 · published 16 March 2026

CVE-2025-62319: Hcltech unica sql injection vulnerability

Hcltech · Unica

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition evaluates to true or false. This allows an attacker to inject arbitrary SQL into backend configuration queries executed within the application.

9.8 CVSS 3.1 Critical EPSS 0.28% · top 81.6% CWE-89 · SQL injection
9.8CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition evaluates to true or false. This allows an attacker to inject arbitrary SQL into backend configuration queries executed within the application.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-62319 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-37497Hcltech unica xml external entity (xxe) vulnerabilityThe Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights …EPSS 0.53%8.8CVE-2023-37498Hcltech unica vulnerabilityA user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued by an administrator.  It is possible that an attacker…EPSS 0.57%7.5CVE-2025-51735Hcltech unica csv injection vulnerabilityCSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.EPSS 0.34%7.5CVE-2025-31996Hcltech unica vulnerabilityHCL Unica Platform is affected by unprotected files due to improper access controls.  These files may contain sensitive information such as private o…EPSS 0.24%7.5CVE-2025-52616Hcltech unica vulnerabilityHCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerab…EPSS 0.26%7.5CVE-2021-27777Hcltech unica xml injection vulnerabilityXML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validatio…EPSS 0.83%6.3CVE-2025-51736Hcltech unica unrestricted file upload vulnerabilityFile upload vulnerability in HCL Technologies Ltd. Unica 12.0.0.EPSS 0.20%6.1CVE-2025-62320Hcltech unica cross-site scripting vulnerabilityHTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Becau…EPSS 0.16%

Source: NIST National Vulnerability Database (record CVE-2025-62319), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.