Junglewise Threat Intelligence

CVE-2025-7047: Utarit Informatics Services SoliClub missing authorization

CVE-2025-7047 · Severity: medium · CVSS 4.3 · Published 2025-12-18

Technologies: Utarit Soliclub. Vendors: Utarit.

Executive brief

A security flaw in the SoliClub application by Utarit Informatics Services Inc. could allow users to perform actions or access information beyond their intended permission levels. SoliClub is a platform used for campus and corporate services like payments and access control. An attacker with a standard user account could exploit this to abuse system privileges, potentially leading to unauthorized data access or misuse of service features.

Technical details

A missing authorization vulnerability (CWE-862) exists in Utarit Informatics Services Inc. SoliClub before version 5.3.7. The application fails to properly verify if a user has the necessary permissions to perform specific actions or access certain resources. An attacker authenticated with low-level privileges can exploit this over the network to perform unauthorized operations or escalate their influence within the application. The vulnerability was addressed in version 5.3.7.

Affected products

  • Utarit Informatics Services Inc. SoliClub before 5.3.7

Timeline

  • 2025-12-18: disclosed
  • 2025-12-18: advisory

References

Related threats