CVE-2018-25129

SOCA Access Control System 180612 contains multiple insecure direct object reference vulnerabilities that allow attackers to access sensitive user credentials. Attackers can retrieve authenticated and unauthenticated user password hashes and pins through unprotected endpoints like Get_Permissions_From_DB.php and Ac10_ReadSortCard.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-24 20:15

Updated : 2025-12-29 15:58


NVD link : CVE-2018-25129

Mitre link : CVE-2018-25129

CVE.ORG link : CVE-2018-25129


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key