PT-2026-1674 · Unknown · Soca Access Control System

Published

2026-01-07

·

Updated

2026-01-08

·

CVE-2019-25270

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SOCA Access Control System version 180612
Description The SOCA Access Control System contains a cross-site scripting issue in the senddata POST parameter of the 'logged page.php' file. This allows attackers to inject malicious scripts by sending crafted POST requests, potentially executing arbitrary HTML and script code within a victim’s browser session. The API endpoint involved is 'logged page.php'. The vulnerable parameter is senddata.
Recommendations Apply input validation and output encoding to the senddata POST parameter in the 'logged page.php' file to prevent the injection of malicious scripts. As a temporary workaround, consider restricting access to the 'logged page.php' file to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25270

Affected Products

Soca Access Control System