PT-2025-23981 · Unknown · Brilliance Golden Link Secondary System

Sechzredo

·

Published

2025-06-05

·

Updated

2025-11-06

·

CVE-2025-5696

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Brilliance Golden Link Secondary System up to 20250424
Description A critical issue was found in the Brilliance Golden Link Secondary System. The problem affects the file /storagework/rentChangeCheckInfoPage.htm and is related to the manipulation of the clientname argument, which leads to SQL injection. This issue can be exploited remotely.
Recommendations For Brilliance Golden Link Secondary System up to 20250424, consider restricting access to the /storagework/rentChangeCheckInfoPage.htm file and avoid using the clientname argument until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-5696

Affected Products

Brilliance Golden Link Secondary System