Executive brief
A security flaw in the SoliClub application by Utarit Informatics Services Inc. could allow users to perform actions or access information beyond their intended permission levels. SoliClub is a platform used for campus and corporate services like payments and access control. An attacker with a standard user account could exploit this to abuse system privileges, potentially leading to unauthorized data access or misuse of service features.
Technical details
A missing authorization vulnerability (CWE-862) exists in Utarit Informatics Services Inc. SoliClub before version 5.3.7. The application fails to properly verify if a user has the necessary permissions to perform specific actions or access certain resources. An attacker authenticated with low-level privileges can exploit this over the network to perform unauthorized operations or escalate their influence within the application. The vulnerability was addressed in version 5.3.7.
Affected products
- Utarit Informatics Services Inc. SoliClub before 5.3.7
Timeline
- 2025-12-18: disclosed
- 2025-12-18: advisory