PT-2025-17616 · Unknown · Meon Bidding Solutions

Published

2025-04-23

·

Updated

2025-04-23

·

CVE-2025-42605

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Meon Bidding Solutions (affected versions not specified)
Description This issue exists due to improper authorization controls on certain API endpoints for the initiation, modification, or cancellation operations. An authenticated remote attacker could exploit this by manipulating parameters in the API request body to gain unauthorized access to other user accounts. Successful exploitation could allow a remote attacker to perform authorized manipulation of data associated with other user accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

BDU:2025-16491
CVE-2025-42605

Affected Products

Meon Bidding Solutions