Executive brief
GastroMenum Web Panel is a restaurant management system used to handle orders, menus, and customer accounts. A flaw in the system reveals whether user accounts exist through differences in server responses, allowing attackers to enumerate valid email addresses or usernames without authentication. This information could be used as a starting point for targeted attacks or account takeover attempts.
Technical details
An observable response discrepancy vulnerability exists in GastroMenum Web Panel that allows account enumeration. The vulnerability is rooted in inconsistent HTTP responses when processing login or account lookup requests—the server returns different status codes or message content depending on whether an account exists. An unauthenticated network attacker can exploit this by submitting a list of potential usernames or email addresses and analyzing server responses to identify valid accounts. No authentication or user interaction is required. This information disclosure enables account footprinting and facilitates subsequent targeted attacks. Patches are available in versions released after August 31, 2026.
Affected products
- GastroMenum Web Panel before 31.08.2026
Timeline
- 2026-09-04: disclosed
- 2026-08-31: patched