API Information Disclosure in Meon KYC Solutions
CVE-2025-42604

6.9MEDIUM

Key Information:

Vendor

Meon

Vendor
CVE Published:
23 April 2025

What is CVE-2025-42604?

A vulnerability in Meon KYC Solutions arises from the enabling of debug mode on specific API endpoints. This configuration flaw allows remote attackers to gain unauthorized access, resulting in the exposure of sensitive system-related information through detailed error messages. Such access can facilitate various malicious activities, including further attacks against the system that exploited this oversight.

Affected Version(s)

KYC solutions 1.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability is reported by Mohit Gadiya.
.