There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.
History

Mon, 12 May 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte zxcloud Goldendb
CPEs cpe:2.3:a:zte:zxcloud_goldendb:*:*:*:*:*:*:*:*
cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:-:*:*:*
Vendors & Products Zte
Zte zxcloud Goldendb

Mon, 28 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 27 Apr 2025 01:45:00 +0000

Type Values Removed Values Added
Description There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.
Title ZTE GoldenDB Database product has SQL injection vulnerabilities in multiple interfaces
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published: 2025-04-27T01:30:44.458Z

Updated: 2025-04-28T15:33:52.903Z

Reserved: 2025-04-25T00:28:13.908Z

Link: CVE-2025-46578

cve-icon Vulnrichment

Updated: 2025-04-28T13:42:41.841Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-27T02:15:16.080

Modified: 2025-05-12T19:32:35.470

Link: CVE-2025-46578

cve-icon Redhat

No data.