Junglewise Threat Intelligence

CVE-2025-61220: AutoBizLine MySecondLine auth bypass in verification mechanism

CVE-2025-61220 · Severity: high · CVSS 7.5 · Published 2025-10-21

Executive brief

The MySecondLine mobile application by AutoBizLine contains a security flaw in how it verifies user identities. This vulnerability allows an unauthorized person to bypass security checks and log in as a different user. Once logged in, the attacker can access the victim's personal information and private account data.

Technical details

A vulnerability in the authentication logic of AutoBizLine com.mysecondline.app 1.2.91 stems from an incomplete verification mechanism. The flaw resides in the user session management or login verification component, potentially involving the 'get_user' endpoint. A remote, unauthenticated attacker can exploit this to impersonate other users without providing valid credentials. Successful exploitation results in unauthorized access to sensitive user data (CWE-200). The vulnerability is confirmed to have a public proof-of-concept.

Affected products

  • AutoBizLine com.mysecondline.app (MySecondLine) 1.2.91

Timeline

  • 2025-10-21: advisory: Initial disclosure date

References