Junglewise Threat Intelligence

CVE-2025-7013: QR Menu Pro Smart Menu Systems authorization bypass in Menu Panel

CVE-2025-7013 · Severity: medium · CVSS 5.7 · Published 2026-01-29

Executive brief

QR Menu Pro Smart Menu Systems, a digital menu platform for restaurants, contains a security flaw in its Menu Panel. This vulnerability allows unauthorized individuals to bypass security checks by manipulating identifiers, potentially leading to the exposure of sensitive customer or business data. An attacker could exploit this to gain access to administrative functions or private information without proper credentials.

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). It occurs in the Menu Panel component of QR Menu Pro Smart Menu Systems, where the application fails to properly validate user-supplied keys or identifiers used for authorization. A remote attacker can manipulate these identifiers to access resources or perform actions belonging to other users or administrators. While one reporting source suggests a medium severity requiring user interaction, the NIST NVD assessment identifies this as a critical network-based attack requiring no authentication or user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. No official patch has been confirmed as the vendor did not respond to disclosure attempts.

Affected products

  • QR Menu Pro Smart Menu Systems Menu Panel through 29012026

Timeline

  • 2026-01-29: disclosed: Initial disclosure by TR-CERT (USOM)
  • 2026-01-29: advisory: CVE-2025-7013 published

References

Related threats