CVE-2018-25361
Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 7EPSS 0.1%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
25 May 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and access all stored data, chats, images, and files without knowing the original passcode.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Soroush · Soroush IM Desktop Apppublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/45171unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →