There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.
Metrics
Affected Vendors & Products
References
History
Mon, 12 May 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Zte
Zte zxcloud Goldendb |
|
CPEs | cpe:2.3:a:zte:zxcloud_goldendb:*:*:*:*:*:*:*:* cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:-:*:*:* cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:lite:*:*:* |
|
Vendors & Products |
Zte
Zte zxcloud Goldendb |
Mon, 28 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 27 Apr 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed. | |
Title | ZTE GoldenDB Database product has a DDE injection vulnerability | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: zte
Published:
Updated: 2025-04-28T15:33:46.289Z
Reserved: 2025-04-25T00:28:13.908Z
Link: CVE-2025-46579

Updated: 2025-04-28T13:42:40.541Z

Status : Analyzed
Published: 2025-04-27T02:15:16.203
Modified: 2025-05-12T19:32:17.170
Link: CVE-2025-46579

No data.