PT-2025-50326 · Tac Information Services Internal External Trade · Goldenhorn

Samet Yilmaz

·

Published

2025-12-10

·

Updated

2026-06-04

·

CVE-2025-13127

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions TAC Information Services Internal and External Trade Inc. GoldenHorn versions prior to 4.25.1121.1
Description GoldenHorn contains a flaw related to improper input neutralization during web page generation, which allows for Cross-Site Scripting (XSS). This issue could potentially allow an attacker to inject malicious scripts into web pages viewed by other users.
Recommendations Update GoldenHorn to version 4.25.1121.1 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13127

Affected Products

Goldenhorn