Executive brief
A security vulnerability has been identified in Restajet's Online Food Delivery System, a platform used for managing food orders and deliveries. This flaw allows an attacker to trick a legitimate user's browser into performing unauthorized actions on their behalf. This could lead to unauthorized changes to account settings, order modifications, or other administrative actions without the user's consent.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Restajet Online Food Delivery System through version 19122025. The application fails to properly validate request tokens, allowing an attacker to craft malicious requests that are executed in the context of a victim's authenticated session. While the CVSS vector indicates low privileges are required, the primary attack vector involves network-based exploitation where a victim is induced to perform an action. Successful exploitation can allow an attacker to perform unauthorized state-changing operations, such as modifying user data or system configurations. As of the disclosure date, the vendor has not responded to reports of this vulnerability.
Affected products
- Restajet Information Technologies Inc. Online Food Delivery System through 19122025
Timeline
- 2025-12-19: disclosed: Initial disclosure by TR-CERT (USOM)
- 2025-12-19: advisory: NVD publication date