Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-46579


There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.


Published

2025-04-27T02:15:16.203

Last Modified

2025-05-12T19:32:17.170

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-94
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zte zxcloud_goldendb < 6.1.03.11 Yes
Application zte zxcloud_goldendb 7.2.01.01 Yes
Application zte zxcloud_goldendb 7.2.01.01 Yes

References