SQL Injection Vulnerability in Golden Link Secondary System
CVE-2025-4352
Key Information:
- Vendor
- Golden Link
- Status
- Vendor
- CVE Published:
- 6 May 2025
Badges
Summary
A vulnerability has been identified in the Golden Link Secondary System, specifically affecting the processing of the file /reprotframework/tcEntrFlowSelect.htm. The issue arises through improper handling of the argument custTradeId, which enables SQL injection attacks. This SQL injection vulnerability can be exploited by remote attackers, allowing them unauthorized access to the database and potentially sensitive information. Given that the exploit has been made public, organizations using the affected version should prioritize patching to mitigate risk.
Affected Version(s)
Secondary System 20250424
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved