CVE-2025-1030

7.5

Utarit Informatics · SoliClub

A vulnerability in Utarit Informatics SoliClub allows unauthenticated actors to access private personal information via the query system.

Executive summary

An unauthenticated information exposure vulnerability in Utarit Informatics SoliClub poses a significant risk to user data privacy.

Vulnerability

This vulnerability involves the exposure of private personal information (CWE-359) through the application query system. The vulnerability is exploitable by an unauthenticated remote attacker with no user interaction required.

Business impact

The successful exploitation of this flaw allows unauthorized actors to access sensitive private data, leading to potential data breaches, privacy violations, and regulatory non-compliance. With a CVSS score of 7.5, the vulnerability is classified as High severity because it allows for the remote, unauthenticated harvesting of internal information, which could facilitate further targeted attacks against the organization.

Remediation

Immediate Action: Update the SoliClub application to version 5.3.7 or the latest available version provided by the vendor to remediate the exposure.

Proactive Monitoring: Review application access logs for unusual query patterns or spikes in requests directed at the information retrieval endpoints.

Compensating Controls: Implement strict network access controls or a Web Application Firewall (WAF) to restrict access to the affected query system until the software patch can be applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the High severity of this information exposure vulnerability, immediate action is required to protect sensitive data. Organizations running affected versions of SoliClub must prioritize upgrading to version 5.3.7 to close this security gap. If an immediate update is not feasible, restrict access to the vulnerable system to prevent unauthorized exploitation.

More Utarit Informatics CVEs

Sources

Originally found and disclosed by Mustafa Anıl YILDIRIM, per the CVE Program record.