Improper Authorization in Meon Bidding Solutions API
CVE-2025-42605
9.3CRITICAL
What is CVE-2025-42605?
A security flaw in Meon Bidding Solutions allows authenticated remote attackers to exploit weaknesses in API endpoint authorization controls. By manipulating parameters in the API request body, an attacker could gain unauthorized access to other user accounts, enabling them to perform unauthorized data manipulation. This vulnerability underscores the importance of robust authorization mechanisms to protect sensitive user data and maintain data integrity.
Affected Version(s)
Bidding Solutions 1.2
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability is reported by Mohit Gadiya.
