Junglewise Threat Intelligence

CVE-2025-13474: Menulux Mobile App authorization bypass via user-controlled key

CVE-2025-13474 · Severity: high · CVSS 7.5 · Published 2025-12-16

Vendors: Menulux Software Inc..

Executive brief

A vulnerability exists in the Menulux mobile application, which is used for digital menus and restaurant management. An attacker can bypass security checks by manipulating user-controlled identifiers, potentially allowing them to access sensitive information belonging to other users or the business. This could lead to unauthorized data exposure and a breach of customer privacy.

Technical details

An authorization bypass vulnerability (CWE-639) exists in the Menulux Mobile App prior to version 9.5.8. The flaw stems from the application's reliance on user-provided keys or identifiers to perform authorization checks without sufficient server-side validation. A remote, unauthenticated attacker can exploit this by supplying a different user's identifier to the application's API or backend services. Successful exploitation allows the attacker to access sensitive data (Confidentiality: High) that they are not authorized to view. The issue is resolved in version 9.5.8.

Affected products

  • Menulux Software Inc. Mobile App before 9.5.8

Timeline

  • 2025-12-16: disclosed
  • 2025-12-16: advisory

References