Executive brief
QR Menu Pro Smart Menu Systems, a digital menu platform for restaurants, contains a security flaw in its Menu Panel. This vulnerability allows unauthorized individuals to bypass security checks by manipulating identifiers, potentially leading to the exposure of sensitive customer or business data. An attacker could exploit this to gain access to administrative functions or private information without proper credentials.
Technical details
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). It occurs in the Menu Panel component of QR Menu Pro Smart Menu Systems, where the application fails to properly validate user-supplied keys or identifiers used for authorization. A remote attacker can manipulate these identifiers to access resources or perform actions belonging to other users or administrators. While one reporting source suggests a medium severity requiring user interaction, the NIST NVD assessment identifies this as a critical network-based attack requiring no authentication or user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. No official patch has been confirmed as the vendor did not respond to disclosure attempts.
Affected products
- QR Menu Pro Smart Menu Systems Menu Panel through 29012026
Timeline
- 2026-01-29: disclosed: Initial disclosure by TR-CERT (USOM)
- 2026-01-29: advisory: CVE-2025-7013 published