CVE-2025-65827 Details
Description
The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over HTTP. As a result, an adversary located "upstream" can intercept the traffic, inspect its contents, and modify the requests in transit. TThis may result in a total compromise of the user's account if the attacker intercepts a request with active authentication tokens or cracks the MD5 hash sent on login.
A vulnerability exists in the Meatmeet Pro mobile application version 1.1.2.0, allowing clear text traffic to all domains. The application communicates with an API server over HTTP, which can be intercepted by an adversary upstream. This interception could lead to a complete compromise of the user's account if authentication tokens are captured or if the MD5 hash used for login is cracked.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| meatmeet meatmeet | 1.1.2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 30, 2025 | Initial Analysis | [email protected] |
| Dec 11, 2025 | CVE Modified | CISA-ADP |
| Dec 10, 2025 | New CVE Received | [email protected] |