Universal FlexCity/Kiosk是土耳其Universal公司的一个智慧城市自助服务终端个系统。 Universal FlexCity/Kiosk 1.0.36之前版本存在访问控制错误漏洞,该漏洞源于特权定义包含不安全操作以及对关键功能缺少身份验证,可能导致访问控制列表未正确约束的功能和权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Universal Software Inc. | FlexCity/Kiosk | 1.0< 1.0.36 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Universal Software Inc. | FlexCity/Kiosk | 1.0 ~ 1.0.36 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-1618 | 8.8 HIGH | Admin Account Takeover in Universal Sotware's FlexCity/Kiosk |
| CVE-2026-1619 | 8.3 HIGH | IDOR in Universal Sotware's FlexCity/Kiosk |
No comments yet