Executive brief
Akın Software's QR Menu, a digital menu platform for restaurants and businesses, contains a security flaw that could allow an attacker to hijack a user's session. By tricking a user into using a pre-determined session identifier, an attacker can gain unauthorized access to the user's account or sensitive information. This could lead to the exposure of customer data or unauthorized changes to menu configurations.
Technical details
A session fixation vulnerability (CWE-384) exists in Akın Software QR Menu versions prior to s1.05.12. The application fails to invalidate existing session identifiers or issue new ones upon user authentication, allowing an attacker to fixate a victim's session ID. An attacker can exploit this by providing a known session ID to a victim (typically requiring some user interaction) and then hijacking the session once the victim authenticates. This vulnerability is reachable over the network and requires low privileges to initiate, potentially leading to a loss of confidentiality. The issue is addressed in version s1.05.12.
Affected products
- Akın Software Computer Import Export Industry and Trade Ltd. QR Menu before s1.05.12
Timeline
- 2026-01-29: disclosed: Initial publication of the CVE record.
- 2026-01-29: advisory: Advisory published by USOM (TR-CERT).
- 2026-03-09: other: NVD enrichment and CPE configuration added.