This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API endpoints. A remote attacker could exploit this vulnerability by intercepting the request and removing the Captcha parameter leading to bypassing the Captcha verification mechanism.
CVSS
No CVSS.
References
Configurations
No configuration.
History
23 Apr 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-23 11:15
Updated : 2025-04-23 14:08
NVD link : CVE-2025-42601
Mitre link : CVE-2025-42601
CVE.ORG link : CVE-2025-42601
JSON object : View
Products Affected
No product.
CWE
CWE-602
Client-Side Enforcement of Server-Side Security