PT-2025-53350 · Unknown · Soca Access Control System
Published
2025-12-24
·
Updated
2025-12-24
·
CVE-2018-25129
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SOCA Access Control System version 180612
Description
The SOCA Access Control System has multiple insecure direct object reference issues. These allow attackers to access sensitive user credentials, including retrieving authenticated and unauthenticated user password hashes and pins. Access is gained through unprotected endpoints such as
/Get Permissions From DB.php and /Ac10 ReadSortCard. The vulnerable parameters or variables are not specified.Recommendations
Apply necessary access controls to the
/Get Permissions From DB.php endpoint.
Apply necessary access controls to the /Ac10 ReadSortCard endpoint.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soca Access Control System