216.73.216.6

CVE-2025-42603

· Published 23/04/2025 11:15 · Modified 23/04/2025 14:08

Labels: CVE-2025-42603 2025-04-23CVE-2025-42603CWE-319[email protected]

Essential information

Published
23/04/2025 11:15
Modified
23/04/2025 14:08
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

This vulnerability exists in the Meon KYC solutions due to transmission of sensitive data in plain text within the response payloads of certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting API response that contains unencrypted sensitive information belonging to other users. Successful exploitation of this vulnerability could allow remote attacker to impersonate the target user and gain unauthorized access to the user account.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
meon / kyc solutions cpe:2.3:a:meon:kyc_solutions:*:*:*:*:*:*:*:*

References