SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through unvalidated POST parameters. Attackers can bypass authentication, retrieve password hashes, and gain administrative access with full system privileges by exploiting injection flaws in Login.php and Card_Edit_GetJson.php.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-24 20:15
Updated : 2025-12-29 15:58
NVD link : CVE-2018-25128
Mitre link : CVE-2018-25128
CVE.ORG link : CVE-2018-25128
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
