Executive brief
Utarit SoliClub, a platform used for campus and corporate smart card management and mobile payments, contains a security flaw where login credentials are permanently embedded in the software. An unauthorized person could use these fixed credentials to bypass security measures and gain access to the system. This could lead to the unauthorized viewing of user data or abuse of account services.
Technical details
A use of hard-coded credentials vulnerability (CWE-798) exists in Utarit SoliClub before version 5.3.7. The application contains static, embedded authentication secrets that can be discovered through reverse engineering or static analysis of the software. A remote, unauthenticated attacker can utilize these credentials to bypass standard authentication mechanisms and gain unauthorized access to the application's functions or data. The vulnerability is exploitable over the network without user interaction. Users are advised to update to version 5.3.7 or later to remediate this issue.
Affected products
- Utarit Informatics Services Inc. SoliClub before 5.3.7
Timeline
- 2025-12-18: disclosed
- 2025-12-18: advisory