First published: Thu Mar 13 2025(Updated: )
This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanism in its API based login. A remote attacker with valid credentials could exploit this vulnerability by manipulating API request URL/payload. Successful exploitation of this vulnerability could allow the attacker to bypass Two-Factor Authentication (2FA) for other user accounts.
Credit: vdisclose@cert-in.org.in
Affected Software | Affected Version | How to fix |
---|---|---|
CAP back office application |
Upgrade Rising Technosoft CAP back office application to the version 2.0.4 or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29996 is classified as a critical vulnerability due to its potential for remote exploitation by attackers.
To fix CVE-2025-29996, ensure that the OTP verification mechanism in the CAP back office application is properly implemented and securely configured.
CVE-2025-29996 affects the CAP back office application that utilizes an API-based login mechanism.
A remote attacker with valid credentials can exploit CVE-2025-29996 by manipulating the API request URL or payload.
Successful exploitation of CVE-2025-29996 could allow attackers to bypass authentication and gain unauthorized access to the application.