Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-25129. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an insecure direct object reference vulnerability in SOCA Access Control System, allowing unauthenticated and authenticated information disclosure of user password hashes and PINs via specific API endpoints.
Description
SOCA Access Control System 180612 contains multiple insecure direct object reference vulnerabilities that allow attackers to access sensitive user credentials. Attackers can retrieve authenticated and unauthenticated user password hashes and pins through unprotected endpoints like Get_Permissions_From_DB.php and Ac10_ReadSortCard.
Exploits (1)
This exploit demonstrates an insecure direct object reference vulnerability in SOCA Access Control System, allowing unauthenticated and authenticated information disclosure of user password hashes and PINs via specific API endpoints.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N