Executive brief
A security flaw exists in the QR Menu Pro Smart Menu Systems, a platform used by restaurants to manage digital menus. This vulnerability allows an attacker to hijack a legitimate user's session, potentially gaining unauthorized access to the management panel. Such access could lead to unauthorized changes to menu items, pricing, or the theft of sensitive administrative information.
Technical details
A session fixation vulnerability (CWE-384) exists in the QR Menu Pro Smart Menu Systems Menu Panel. The flaw allows a remote attacker to fix a user's session identifier, leading to session hijacking if the victim authenticates using the pre-set ID. The attack requires network reachability and some user interaction. While the CNA reported a medium severity, NIST's analysis elevated the score to 8.8 (High) due to the potential for full compromise of confidentiality, integrity, and availability. As of the disclosure, the vendor has not responded to reports, and no official patch has been confirmed.
Affected products
- QR Menu Pro Smart Menu Systems Menu Panel through 29012026
Timeline
- 2026-01-29: disclosed: Initial disclosure by USOM/TR-CERT
- 2026-01-29: advisory: NVD published the CVE record
- 2026-06-05: other: NVD record modified with enriched data