Description
This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API endpoints of authentication process. A remote attacker could exploit this vulnerability by intercepting and manipulating the responses through API request body leading to unauthorized access of other user accounts.
Scores
CVSS v4
8.2
EPSS
0.0056
EPSS Percentile
68.5%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-384
CWE-613
Status
published
Products (1)
Meon/KYC solutions
1.1
Published
Apr 23, 2025
Tracked Since
Feb 18, 2026