Executive brief
AKIN Software QRMenu, a digital menu system used by restaurants and hospitality businesses, contains a security flaw that allows unauthorized access to sensitive information. By manipulating specific identifiers in web requests, an attacker can bypass security checks to view data they are not permitted to see. This could lead to the exposure of customer or business information, potentially impacting operational privacy and reputation.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in AKIN Software QRMenu. The flaw allows a remote, unauthenticated attacker to access restricted resources or data by modifying key input parameters that the application uses to identify objects. The vulnerability is exploitable over the network with low complexity and requires no user interaction. Successful exploitation allows the attacker to bypass authorization logic and achieve privilege abuse, specifically impacting data confidentiality. A fix was released in the version dated September 5, 2025.
Affected products
- AKIN Software Computer Import Export Industry and Trade Co. Ltd. QRMenu 1.05.12 to 2025-05-09 (exclusive)
Timeline
- 2025-09-05: patched: Version dated 05.09.2025 released to address the issue.
- 2025-10-13: disclosed: Initial vulnerability disclosure.
- 2025-10-13: advisory: NVD published the CVE record.