PT-2026-1674 · Unknown · Soca Access Control System
Published
2026-01-07
·
Updated
2026-01-08
·
CVE-2019-25270
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SOCA Access Control System version 180612
Description
The SOCA Access Control System contains a cross-site scripting issue in the
senddata POST parameter of the 'logged page.php' file. This allows attackers to inject malicious scripts by sending crafted POST requests, potentially executing arbitrary HTML and script code within a victim’s browser session. The API endpoint involved is 'logged page.php'. The vulnerable parameter is senddata.Recommendations
Apply input validation and output encoding to the
senddata POST parameter in the 'logged page.php' file to prevent the injection of malicious scripts. As a temporary workaround, consider restricting access to the 'logged page.php' file to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soca Access Control System