Executive brief
Akınsoft QR Menü, a digital menu platform for restaurants and cafes, contains a security flaw that allows attackers to redirect users to malicious websites. By tricking a customer or staff member into clicking a specially crafted link, an attacker can facilitate phishing attacks to steal credentials or distribute malware. This can lead to reputational damage and potential compromise of user accounts.
Technical details
An Open Redirect vulnerability (CWE-601) exists in Akınsoft QR Menü versions s1.05.05 through v1.05.12. The application fails to properly validate user-supplied input used in redirection targets, allowing a remote attacker to craft a URL that redirects victims to an arbitrary external domain. Exploitation requires minimal user interaction, typically via a phishing link. Successful exploitation can be used to conduct phishing campaigns, bypass security filters, or perform forceful browsing attacks. The issue is addressed in version v1.05.12.
Affected products
- Akınsoft QR Menü s1.05.05 to v1.05.12
Timeline
- 2025-09-01: disclosed
- 2025-09-01: advisory