Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and access all stored data, chats, images, and files without knowing the original passcode.
Metrics
Affected Vendors & Products
References
History
Tue, 26 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soroush
Soroush soroush Messenger |
|
| Vendors & Products |
Soroush
Soroush soroush Messenger |
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and access all stored data, chats, images, and files without knowing the original passcode. | |
| Title | Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-25T14:15:08.685Z
Updated: 2026-05-25T23:41:07.358Z
Reserved: 2026-05-24T13:26:19.658Z
Link: CVE-2018-25361
No data.
Status : Received
Published: 2026-05-25T15:16:18.640
Modified: 2026-05-25T15:16:18.640
Link: CVE-2018-25361
No data.