Description
This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API endpoints. A remote attacker could exploit this vulnerability by intercepting the request and removing the Captcha parameter leading to bypassing the Captcha verification mechanism.
Problem types
CWE-602: Client-Side Enforcement of Server-Side Security
Product status
1.1
Credits
This vulnerability is reported by Mohit Gadiya.
References
www.cert-in.org.in/...eid=PUBVLNOTES01&VLCODE=CIVN-2025-0082
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.