CVE-2025-7358

7.5

Utarit Informatics Services Inc · SoliClub

A hard-coded credential vulnerability in Utarit Informatics Services Inc. SoliClub allows unauthenticated attackers to perform authentication abuse and gain unauthorized access.

Executive summary

The SoliClub platform contains a critical hard-coded credential vulnerability that permits unauthenticated access to sensitive system functions.

Vulnerability

This vulnerability involves the use of hard-coded credentials within the application, which enables authentication abuse. The vulnerability is exploitable by an unauthenticated attacker over the network with low attack complexity.

Business impact

The presence of hard-coded credentials presents a significant risk to organizational security, as it allows unauthorized parties to bypass standard authentication mechanisms entirely. With a CVSS score of 7.5, this flaw poses a high risk of unauthorized data access and potential compromise of system integrity. Failure to address this vulnerability may result in unauthorized data exposure and loss of administrative control over the affected environment.

Remediation

Immediate Action: Update the SoliClub software to version 5.3.7 or later as soon as the vendor makes the security update available.

Proactive Monitoring: Review system authentication logs for unusual login patterns or unauthorized access attempts originating from internal or external sources.

Compensating Controls: Implement strict network segmentation and restrict access to the affected service via a Web Application Firewall or VPN until the software can be updated.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity and the nature of the authentication bypass, this vulnerability should be prioritized for immediate remediation. Organizations must ensure that the vendor provided patch is applied as soon as it is released to prevent unauthorized access. In the interim, isolating the affected application from public-facing network segments is strongly recommended to reduce the attack surface.

More Utarit Informatics Services Inc CVEs

Sources

Originally found and disclosed by Samet ALKIŞ, per the CVE Program record.