CVE-2025-1030
7.5Utarit Informatics · SoliClub
A vulnerability in Utarit Informatics SoliClub allows unauthenticated actors to access private personal information via the query system.
Executive summary
An unauthenticated information exposure vulnerability in Utarit Informatics SoliClub poses a significant risk to user data privacy.
Vulnerability
This vulnerability involves the exposure of private personal information (CWE-359) through the application query system. The vulnerability is exploitable by an unauthenticated remote attacker with no user interaction required.
Business impact
The successful exploitation of this flaw allows unauthorized actors to access sensitive private data, leading to potential data breaches, privacy violations, and regulatory non-compliance. With a CVSS score of 7.5, the vulnerability is classified as High severity because it allows for the remote, unauthenticated harvesting of internal information, which could facilitate further targeted attacks against the organization.
Remediation
Immediate Action: Update the SoliClub application to version 5.3.7 or the latest available version provided by the vendor to remediate the exposure.
Proactive Monitoring: Review application access logs for unusual query patterns or spikes in requests directed at the information retrieval endpoints.
Compensating Controls: Implement strict network access controls or a Web Application Firewall (WAF) to restrict access to the affected query system until the software patch can be applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity of this information exposure vulnerability, immediate action is required to protect sensitive data. Organizations running affected versions of SoliClub must prioritize upgrading to version 5.3.7 to close this security gap. If an immediate update is not feasible, restrict access to the vulnerable system to prevent unauthorized exploitation.
More Utarit Informatics CVEs
Sources
Originally found and disclosed by Mustafa Anıl YILDIRIM, per the CVE Program record.