Description
SOCA Access Control System 180612 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through unvalidated POST parameters. Attackers can bypass authentication, retrieve password hashes, and gain administrative access with full system privileges by exploiting injection flaws in Login.php and Card_Edit_GetJson.php.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
170000
141007
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5519.php
www.exploit-db.com/exploits/46833 (ExploitDB-46833)
www.socatech.com (SOCA Technology Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5519.php (Zero Science Lab Disclosure (ZSL-2019-5519))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.