Executive brief
A vulnerability exists in the Menulux mobile application, which is used for digital menus and restaurant management. An attacker can bypass security checks by manipulating user-controlled identifiers, potentially allowing them to access sensitive information belonging to other users or the business. This could lead to unauthorized data exposure and a breach of customer privacy.
Technical details
An authorization bypass vulnerability (CWE-639) exists in the Menulux Mobile App prior to version 9.5.8. The flaw stems from the application's reliance on user-provided keys or identifiers to perform authorization checks without sufficient server-side validation. A remote, unauthenticated attacker can exploit this by supplying a different user's identifier to the application's API or backend services. Successful exploitation allows the attacker to access sensitive data (Confidentiality: High) that they are not authorized to view. The issue is resolved in version 9.5.8.
Affected products
- Menulux Software Inc. Mobile App before 9.5.8
Timeline
- 2025-12-16: disclosed
- 2025-12-16: advisory