Boolean SQL injection vulnerability in the web app of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows a low level priviliged user that has access to the platform, to execute arbitrary SQL commands via the datafine parameter.
https://github.com/MarioTesoro/vulnerability-research/tree/main/CVE-2025-56700
https://basedigitale.com/integrated-security-solutions/security-asset-management/centrax/