SQL Injection Vulnerability in Brilliance Golden Link Secondary System
CVE-2025-6276
What is CVE-2025-6276?
A notable vulnerability has been identified in the Brilliance Golden Link Secondary System, specifically within an unspecified function of the /storagework/rentTakeInfoPage.htm file. This issue allows for SQL injection through the manipulation of the custTradeName argument, enabling potential attackers to execute unauthorized commands on the database remotely. Given the public disclosure of this exploit, it poses a significant risk to all users operating versions of the system prior to 20250609.
Affected Version(s)
Golden Link Secondary System 20250609
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved