PT-2025-17616 · Unknown · Meon Bidding Solutions
Published
2025-04-23
·
Updated
2025-04-23
·
CVE-2025-42605
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Meon Bidding Solutions (affected versions not specified)
Description
This issue exists due to improper authorization controls on certain API endpoints for the initiation, modification, or cancellation operations. An authenticated remote attacker could exploit this by manipulating parameters in the API request body to gain unauthorized access to other user accounts. Successful exploitation could allow a remote attacker to perform authorized manipulation of data associated with other user accounts.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Meon Bidding Solutions