Junglewise Threat Intelligence

CVE-2025-1031: Utarit SoliClub authorization bypass via user-controlled key

CVE-2025-1031 · Severity: high · CVSS 7.5 · Published 2025-12-18

Technologies: Utarit Soliclub. Vendors: Utarit.

Executive brief

Utarit SoliClub, a campus and corporate life management application, contains a security flaw that allows unauthorized access to sensitive information. By manipulating specific identifiers or keys within the application, an attacker can bypass security checks to access data they are not permitted to see. This could lead to the exposure of personal user information or the misuse of application features. Users should update to version 5.3.7 or later to resolve this issue.

Technical details

An authorization bypass vulnerability exists in Utarit Informatics Services Inc. SoliClub versions 5.2.4 through 5.3.6. The flaw is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the application fails to properly validate that a user has permission to access a resource identified by a specific key or parameter. A remote, unauthenticated attacker can exploit this by modifying these keys in network requests to access data belonging to other users or perform unauthorized actions. The vulnerability is addressed in version 5.3.7.

Affected products

  • Utarit Informatics Services Inc. SoliClub 5.2.4 to 5.3.7

Timeline

  • 2025-12-18: advisory: Initial disclosure by TR-CERT/USOM
  • 2025-12-18: disclosed

References

Related threats