Executive brief
GOLDENHORN ONEIT is a trade finance and logistics management system used by import/export businesses to process transactions and manage shipments. A SQL injection vulnerability allows attackers to extract or manipulate sensitive business data including customer information, transaction records, and payment details without authentication.
Technical details
This vulnerability is a blind SQL injection flaw in GOLDENHORN ONEIT that fails to properly sanitize user-supplied input before incorporating it into SQL queries. An attacker can exploit this via the application's input fields to execute arbitrary database queries and extract sensitive information, even though error messages are not displayed (blind injection). The vulnerability is network-accessible and requires no authentication. Exploitation allows unauthorized data extraction or potential database manipulation. Patches are available in version Göbeklitepe and later.
Affected products
- TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT before Göbeklitepe
Timeline
- 2026-09-04: disclosed