Executive brief
Akınsoft QR Menü, a digital menu platform used by restaurants and hospitality businesses, contains a security flaw that could allow unauthorized actions to be performed on the system. An attacker could trick a logged-in user into unknowingly executing administrative or account-level commands, potentially leading to data modification or service disruptions. This could impact business operations and the integrity of the digital menu system.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Akınsoft QR Menü versions s1.05.06 through v1.05.12. The application fails to properly validate requests, allowing an attacker to craft malicious requests that are executed in the context of an authenticated user's session. This vulnerability is reachable over the network and does not require high complexity to exploit. Successful exploitation can lead to unauthorized data modification, information disclosure, or a high impact on service availability. The issue is addressed in version v1.05.12.
Affected products
- Akınsoft QR Menü s1.05.06 to v1.05.12
Timeline
- 2025-09-01: advisory: Initial publication of CVE-2025-0610