Description
SOCA Access Control System 180612 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that submit forged requests to create admin accounts by tricking logged-in users into visiting a malicious site.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
170000
141007
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5520.php
www.exploit-db.com/exploits/46834 (ExploitDB-46834)
www.socatech.com (SOCA Technology Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5520.php (Zero Science Lab Disclosure (ZSL-2019-5520))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.