Executive brief
Universal Software Inc. FlexCity/Kiosk, a platform used for city services and kiosk management, contains a security flaw that allows users to bypass authorization. By manipulating specific identifiers, an attacker can gain unauthorized access to data or functions they should not be able to reach. This could lead to the exposure of sensitive information or unauthorized changes to the system's operations.
Technical details
An Authorization Bypass Through User-Controlled Key (CWE-639) vulnerability exists in Universal Software Inc. FlexCity/Kiosk versions 1.0 through 1.0.36. The flaw allows a remote attacker with low privileges to bypass security checks by providing or manipulating trusted identifiers (such as account IDs or keys) within the application's requests. Successful exploitation enables the attacker to access or modify data belonging to other users or the system. The vulnerability is reachable over the network and has been addressed in version 1.0.36.
Affected products
- Universal Software Inc. (Uni-Yaz) FlexCity/Kiosk 1.0 to 1.0.36
Timeline
- 2026-02-13: advisory: Initial disclosure by TR-CERT
- 2026-02-13: disclosed