Executive brief
Akinsoft ProKuafor, a management software for hair salons and barbers, contains a security flaw that fails to limit the number of login attempts. This allows an attacker to repeatedly guess passwords until they gain unauthorized access to the system. Successful exploitation could lead to the exposure of customer data, appointment schedules, and business financial records.
Technical details
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) within the Akinsoft ProKuafor application. The software lacks a mechanism to throttle or block multiple failed login attempts, enabling a remote, unauthenticated attacker to conduct brute-force or dictionary attacks against the authentication interface. By successfully guessing credentials, the attacker can bypass authentication controls to gain high-level access to the application's data and functionality. The issue affects versions starting from s1.02.08 and is addressed in version v1.02.08.
Affected products
- Akinsoft ProKuafor s1.02.08 before v1.02.08
Timeline
- 2025-09-02: disclosed
- 2025-09-02: advisory