PT-2025-53350 · Unknown · Soca Access Control System

Published

2025-12-24

·

Updated

2025-12-24

·

CVE-2018-25129

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SOCA Access Control System version 180612
Description The SOCA Access Control System has multiple insecure direct object reference issues. These allow attackers to access sensitive user credentials, including retrieving authenticated and unauthenticated user password hashes and pins. Access is gained through unprotected endpoints such as /Get Permissions From DB.php and /Ac10 ReadSortCard. The vulnerable parameters or variables are not specified.
Recommendations Apply necessary access controls to the /Get Permissions From DB.php endpoint. Apply necessary access controls to the /Ac10 ReadSortCard endpoint.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2018-25129

Affected Products

Soca Access Control System