An issue in the Property Tax Payment Portal in Information Kerala Mission SANCHAYA v3.0.4 allows attackers to arbitrarily modify payment amounts via a crafted request.
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.
Link | Tags |
---|---|
https://tax.lsgkerala.gov.in/epayment/QuickPaySearch.php | broken link |
https://github.com/edwin-0990/CVE_ID/blob/main/CVE-2025-25382/README.md | third party advisory |