First published: Sun Apr 27 2025(Updated: )
There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
ZTE GoldenDB |
6.1.03.11,7.2.01.01P1,Lite7.2.01.01P1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-46578 is rated as high due to the potential for attackers to execute SQL injection and extract sensitive data.
To fix CVE-2025-46578, ensure that all input fields in the GoldenDB interfaces are properly sanitized and use prepared statements for database queries.
The potential impacts of CVE-2025-46578 include unauthorized access to sensitive database information and potential data manipulation.
CVE-2025-46578 affects all versions of the ZTE GoldenDB database product that have the identified SQL injection vulnerabilities.
Exploitation of CVE-2025-46578 can be detected by monitoring database logs for unusual query patterns and unauthorized access attempts.