PT-2025-17616 · Unknown · Meon Bidding Solutions

CVE-2025-42605

·

Publicado

2025-04-23

·

Atualizado

2025-04-23

CVSS v4.0

9.4

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Meon Bidding Solutions (affected versions not specified)
Description This issue exists due to improper authorization controls on certain API endpoints for the initiation, modification, or cancellation operations. An authenticated remote attacker could exploit this by manipulating parameters in the API request body to gain unauthorized access to other user accounts. Successful exploitation could allow a remote attacker to perform authorized manipulation of data associated with other user accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-16491
CVE-2025-42605

Produtos afetados

Meon Bidding Solutions