Executive brief
Menulux Portal is a web-based application used for menu management and portal functionality. This vulnerability allows attackers to inject malicious JavaScript code that persists in the application and executes in users' browsers, potentially compromising user sessions, stealing credentials, or defacing content viewed by other portal users.
Technical details
This is a stored cross-site scripting (XSS) vulnerability arising from improper neutralization of user-supplied input during web page generation. The vulnerability exists in Menulux Portal before version 20260903211448. Attackers can inject malicious JavaScript through user-controlled input fields that are stored in the application and later rendered to other users without proper sanitization or encoding. No special authentication or network preconditions have been disclosed. A successful exploit allows arbitrary JavaScript execution in the context of affected users' browsers, enabling session hijacking, credential theft, or malware distribution. A patched version addressing this issue has been released.
Affected products
- Menulux Software Inc. Menulux Portal before 20260903211448
Timeline
- 2026-09-04: disclosed
- 2026-09-03: patched: Version 20260903211448 and later