Executive brief
Menulux Portal is a web application that handles user authentication and account management. A flaw in how the system responds to login attempts allows attackers to determine whether email addresses or usernames exist in the system without valid credentials, facilitating account enumeration and targeted phishing campaigns.
Technical details
This vulnerability is an observable response discrepancy (also known as username enumeration or account footprinting) in Menulux Portal. The root cause is inconsistent or distinguishable error messages or response timing between valid and invalid account credentials during authentication. An attacker can perform account enumeration over the network without authentication by comparing response patterns—for example, detecting different error messages when a user exists versus when they do not. This information enables attackers to build lists of valid accounts for subsequent attacks such as brute-force password attacks or social engineering. The vulnerability affects Menulux Portal versions before 20260903211448, and a patch is available in the published version.
Affected products
- Menulux Software Inc. Menulux Portal before 20260903211448
Timeline
- 2026-09-04: disclosed