Junglewise Threat Intelligence

CVE-2024-12914: Akınsoft QR Menü cross-site scripting

CVE-2024-12914 · Severity: medium · CVSS 4.3 · Published 2025-09-01

Technologies: Akınsoft QR Menü. Vendors: Akınsoft.

Executive brief

Akınsoft QR Menü, a digital menu platform for restaurants and cafes, contains a security vulnerability that could allow an attacker to inject malicious scripts into the web interface. If exploited, this could lead to unauthorized actions being performed in the context of a user's session, potentially compromising administrative accounts or customer interactions. The issue has been addressed in version 1.05.12.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Akınsoft QR Menü versions s1.05.05 through v1.05.12. The flaw stems from improper neutralization of user-supplied input during the generation of web pages (CWE-79). An attacker with high privileges can exploit this over the network, though it requires interaction from another user (typically an administrator) to execute the malicious script. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser session, which can lead to session hijacking or unauthorized data modification. The vulnerability is resolved in version 1.05.12.

Affected products

  • Akınsoft QR Menü s1.05.05 to v1.05.12

Timeline

  • 2025-09-01: disclosed
  • 2025-09-01: advisory

References

Related threats