Junglewise Threat Intelligence

CVE-2025-0670: Akinsoft ProKuafor authorization bypass via user-controlled key

CVE-2025-0670 · Severity: medium · CVSS 4.7 · Published 2025-09-02

Vendors: AKINSOFT.

Executive brief

Akinsoft ProKuafor, a management software for hair salons and barbers, contains a security flaw that allows authorized users to bypass certain restrictions. By manipulating specific data keys, a high-privileged user could access resources or information they are not intended to see. This could lead to unauthorized data exposure or minor disruptions in service operations.

Technical details

An authorization bypass vulnerability (CWE-639) exists in Akinsoft ProKuafor due to improper validation of user-controlled keys. A remote attacker with high-level privileges can manipulate these keys to access resources outside of their intended scope, leading to resource leak exposure. The vulnerability is present in versions starting from s1.02.07 and was addressed in version v1.02.08. The attack requires network connectivity and high administrative privileges but no user interaction.

Affected products

  • Akinsoft ProKuafor From s1.02.07 before v1.02.08

Timeline

  • 2025-09-02: advisory: Initial publication of CVE-2025-0670
  • 2025-09-02: disclosed
  • 2026-06-06: other: Last modified date in NVD record

References

Related threats