First published: Wed Apr 23 2025(Updated: )
This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for the initiation, modification, or cancellation operations. An authenticated remote attacker could exploit this vulnerability by manipulating parameter in the API request body to gain unauthorized access to other user accounts. Successful exploitation of this vulnerability could allow remote attacker to perform authorized manipulation of data associated with other user accounts.
Credit: vdisclose@cert-in.org.in
Affected Software | Affected Version | How to fix |
---|---|---|
Meon Bidding Solutions |
Upgrade Bidding Solutions to version 1.3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-42605 is classified as a high severity vulnerability due to improper authorization controls.
To fix CVE-2025-42605, update Meon Bidding Solutions to the latest version that addresses the improper authorization on API endpoints.
Exploiting CVE-2025-42605 could allow an authenticated attacker to manipulate API parameters, leading to unauthorized initiation, modification, or cancellation operations.
CVE-2025-42605 affects Meon Bidding Solutions due to its vulnerable API endpoints.
CVE-2025-42605 can be exploited by an authenticated remote attacker, indicating a moderate level of complexity for exploitation.