Executive brief
GoldenHorn, a software solution from TAC Information Services, is vulnerable to a security flaw that could allow an attacker to execute malicious scripts in a user's browser. This type of attack, known as Cross-Site Scripting, typically requires a user to interact with a malicious link or page while logged into the system. If successful, an attacker could potentially access sensitive session information or perform actions on behalf of the user.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in TAC Information Services GoldenHorn prior to version 4.25.1121.1. The flaw stems from improper neutralization of user-supplied input during the generation of web pages (CWE-79). An authenticated attacker with low privileges can exploit this vulnerability over the network, though it requires interaction from a victim (UI:R). Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to unauthorized access to sensitive information. A patch is available in version 4.25.1121.1.
Affected products
- TAC Information Services Internal and External Trade Inc. GoldenHorn before 4.25.1121.1
Timeline
- 2025-12-10: advisory: Initial advisory published by TR-CERT