No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soroush
Soroush soroush Messenger |
|
| Vendors & Products |
Soroush
Soroush soroush Messenger |
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption key. Attackers can inject malicious database records into the application's database files to unlock the client and access all stored data, chats, images, and files without knowing the original passcode. | |
| Title | Soroush IM Desktop App 0.17.0 Authentication Bypass via Database Injection | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-27T16:09:54.014Z
Reserved: 2026-05-24T13:26:19.658Z
Link: CVE-2018-25361
Updated: 2026-05-27T16:09:49.472Z
Status : Deferred
Published: 2026-05-25T15:16:18.640
Modified: 2026-05-26T19:47:48.987
Link: CVE-2018-25361
No data.
OpenCVE Enrichment
Updated: 2026-05-26T13:00:44Z