Captcha Bypass Vulnerability in Meon KYC solutions
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.2epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
In short
Meon KYC solutions fails to properly validate captcha responses on the server side, allowing attackers to remove the captcha parameter from requests and bypass the security check entirely.
Technical detail
CWE-602 insufficient server-side validation allows remote attackers to bypass captcha verification by crafting requests with missing or invalid captcha parameters. The vulnerability exists in API endpoints that should enforce captcha validation; exploitation requires no authentication and directly compromises the intended security control.
Summary generated and translated by AI from the official description.
This vulnerability exists in Meon KYC solutions due to insufficient server-side validation of the Captcha in certain API endpoints. A remote attacker could exploit this vulnerability by intercepting the request and removing the Captcha parameter leading to bypassing the Captcha verification mechanism.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Affected products
Meon · KYC solutions