Junglewise Threat Intelligence

CVE-2025-12504: Talent Software UNIS SQL injection

CVE-2025-12504 · Severity: critical · CVSS 9.8 · Published 2025-12-09

Executive brief

Talent Software UNIS, a management software platform, contains a critical security vulnerability that allows unauthorized individuals to manipulate its database. By exploiting this flaw, an attacker could gain full access to sensitive information, modify records, or disrupt the system's operations entirely. This issue can be exploited remotely without requiring any user interaction or valid login credentials.

Technical details

A SQL injection vulnerability (CWE-89) exists in Talent Software UNIS due to improper neutralization of special elements used in SQL commands. The flaw is reachable over the network and requires no authentication (PR:N) or user interaction (UI:N). An attacker can exploit this by sending specially crafted requests to the application, leading to unauthorized data retrieval, modification, or deletion within the database. The vulnerability affects all versions of UNIS prior to 42321. A patch is available in version 42321.

Affected products

  • Talent Software UNIS before 42321

Timeline

  • 2025-12-09: advisory: Initial disclosure by USOM/TR-CERT
  • 2025-12-09: disclosed: CVE-2025-12504 published

References

Related threats