Executive brief
Akinsoft MyRezzta, a restaurant management and reservation platform, contains a security flaw that fails to limit the number of login attempts. This allows unauthorized individuals to gain access to administrative or user accounts by repeatedly guessing passwords or exploiting the password recovery process. Successful exploitation could lead to a total compromise of the system, including access to customer data and business operations.
Technical details
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) within the Akinsoft MyRezzta application. It stems from a lack of rate-limiting or account lockout mechanisms on authentication endpoints and password recovery features. A remote, unauthenticated attacker can launch automated brute-force attacks to guess credentials or manipulate the password recovery flow to bypass authentication entirely. The flaw is reachable over the network without user interaction and affects versions s2.03.01 through v2.05.01. Users are advised to update to version v2.05.01 or later.
Affected products
- Akinsoft MyRezzta from s2.03.01 before v2.05.01
Timeline
- 2025-09-03: advisory: Initial disclosure by TR-CERT (USOM)
- 2025-09-03: disclosed: CVE-2025-1740 published