CVE-2025-42604 Details
Description
This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unauthorized API endpoints leading to detailed error messages as response leading to disclosure of system related information.
A vulnerability in Meon KYC solutions exists because debug mode is enabled on certain API endpoints. This allows remote attackers to access unauthorized API endpoints, resulting in detailed error messages that disclose system-related information. The vulnerability affects Meon KYC Solutions version 1.1.
Users are advised to upgrade Meon KYC Solutions to version 1.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 23, 2025CISA-ADP
Assessed Apr 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0082 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1295 | Debug Messages Revealing Unnecessary Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Meon KYC Solutions | All versions |
CPE
Remediation
| |
| Meon Bidding Solutions | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2025 | New CVE Received | [email protected] |
Volerion