QSearchQSearch

CVE-2018-25361

6.8 MEDIUM

Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injectin...

Published: 2026-05-25 · Last updated: 2026-05-26

Severity and scoring

CVSS
6.8 MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE
CWE-290

Description

Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and access all stored data, chats, images, and files without knowing the original passcode.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-53857 OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowF... (8.1 HIGH)
  • CVE-2026-53849 OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account i... (8.1 HIGH)
  • CVE-2026-42662 Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions (6.5 MEDIUM)
  • CVE-2026-27089 Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions (7.5 HIGH)
  • CVE-2026-36537 ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange (9.8 CRITICAL)