An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.
References
| Link | Resource |
|---|---|
| https://github.com/edwin-0990/CVE_ID/blob/main/CVE-2025-25382/README.md | Third Party Advisory |
| https://tax.lsgkerala.gov.in/epayment/QuickPaySearch.php | Broken Link |
| https://github.com/edwin-0990/CVE_ID/blob/main/CVE-2025-25382/README.md | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-03-10 16:15
Updated : 2025-06-23 19:49
NVD link : CVE-2025-25382
Mitre link : CVE-2025-25382
CVE.ORG link : CVE-2025-25382
JSON object : View
Products Affected
ikm
- sanchaya
CWE
CWE-472
External Control of Assumed-Immutable Web Parameter
