Executive brief
Akinsoft MyRezzta, a restaurant management and reservation platform, contains a security flaw that allows users to bypass authorization controls. By manipulating specific identifiers in their web browser, an attacker could access data or pages they are not permitted to see. This could lead to the exposure of sensitive customer information or unauthorized access to management functions.
Technical details
An Authorization Bypass Through User-Controlled Key (CWE-639) vulnerability exists in Akinsoft MyRezzta versions s2.02.02 through v2.05.01. The flaw allows an authenticated attacker to perform 'forceful browsing' by modifying keys or identifiers within the application's requests to access objects or records belonging to other users. The attack is network-reachable and requires low privileges, though it is noted to require some level of user interaction according to the CVSS vector. Successful exploitation can lead to high confidentiality impacts. Users are advised to upgrade to version v2.05.01 or later.
Affected products
- Akinsoft MyRezzta s2.02.02 to v2.05.01 (exclusive)
Timeline
- 2025-09-03: advisory: Initial publication of the vulnerability details.