Executive brief
Menulux Portal, a web-based management system, stores sensitive password credentials in plaintext instead of using secure encryption. An attacker who gains access to the application's data or configuration files can retrieve these passwords, compromising accounts and potentially accessing other connected systems or customer data.
Technical details
This vulnerability is a plaintext password storage issue (CWE-256) in Menulux Portal, where sensitive authentication credentials are stored without proper cryptographic protection. An attacker with local file system access, database access, or who can intercept application data in transit can extract plaintext passwords. The vulnerability affects Menulux Portal versions prior to 20260903211448. Exploitation does not require network reachability to the application itself but rather access to where credentials are stored. A patch is available in version 20260903211448 or later.
Affected products
- Menulux Software Inc. Menulux Portal before 20260903211448
Timeline
- 2026-09-04: disclosed