Executive brief
Akinsoft MyRezzta, a restaurant management and reservation platform, contains a vulnerability that allows for resource exhaustion and workflow manipulation. An attacker could exploit this to flood the system with data, potentially causing service slowdowns or outages that disrupt business operations and customer bookings. The issue is resolved in version 2.05.01.
Technical details
The vulnerability stems from CWE-841 (Improper Enforcement of Behavioral Workflow) and CWE-400 (Uncontrolled Resource Consumption) within the Akinsoft MyRezzta application. A remote attacker can exploit these weaknesses to perform input data manipulation and flooding (CAPEC-125), leading to a denial-of-service condition or unauthorized workflow transitions. The attack vector is network-based and requires minimal user interaction, though it does not require prior authentication. The issue affects versions starting from s2.02.02 and is fixed in version v2.05.01.
Affected products
- Akinsoft MyRezzta s2.02.02 to v2.05.01
Timeline
- 2025-09-03: disclosed
- 2025-09-03: advisory