CVE-2025-46579

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
27/04/2025
Last modified:
12/05/2025

Description

There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zte:zxcloud_goldendb:*:*:*:*:*:*:*:* 6.1.03 (including) 6.1.03.11 (excluding)
cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:-:*:*:*
cpe:2.3:a:zte:zxcloud_goldendb:7.2.01.01:-:*:*:lite:*:*:*