There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 27 Apr 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed. | |
Title | ZTE GoldenDB Database product has a DDE injection vulnerability | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: zte
Published: 2025-04-27T01:34:35.034Z
Updated: 2025-04-28T15:33:46.289Z
Reserved: 2025-04-25T00:28:13.908Z
Link: CVE-2025-46579

Updated: 2025-04-28T13:42:40.541Z

Status : Awaiting Analysis
Published: 2025-04-27T02:15:16.203
Modified: 2025-04-29T13:52:10.697
Link: CVE-2025-46579

No data.