Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7epss 0.1%
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and access all stored data, chats, images, and files without knowing the original passcode.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Soroush · Soroush IM Desktop Apppublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/45171unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.