PT-2025-17614 · Unknown · Meon Kyc Solutions

Published

2025-04-23

·

Updated

2025-04-23

·

CVE-2025-42603

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Meon KYC solutions (affected versions not specified)
Description This issue exists due to the transmission of sensitive data in plain text within the response payloads of certain API endpoints. An authenticated remote attacker could exploit this by intercepting API responses that contain unencrypted sensitive information belonging to other users. Successful exploitation could allow a remote attacker to impersonate the target user and gain unauthorized access to the user account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-16493
CVE-2025-42603

Affected Products

Meon Kyc Solutions