CVE-2025-70420

· NIST NVD ↗

A SQL injection vulnerability exists in Genesys Latitude v25.1.0.420 that allows an authenticated attacker to execute arbitrary SQL queries against the backend database. The vulnerability is caused by unsanitized user-supplied input being concatenated directly into SQL statements.

HIGH
CVSS severity
8.8
CVSS base score
2026-04-21
Published

CWE codes

CWE-89

Affected products

genesys:latitude

Sources