Description
This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unauthorized API endpoints leading to detailed error messages as response leading to disclosure of system related information.
Problem types
CWE-1295: Debug Messages Revealing Unnecessary Information
Product status
1.1
Credits
This vulnerability is reported by Mohit Gadiya.
References
www.cert-in.org.in/...eid=PUBVLNOTES01&VLCODE=CIVN-2025-0082