CVE-2025-13474

7.5

Menulux Software · Mobile App

A vulnerability in the Menulux Software Mobile App allows an unauthenticated attacker to perform an authorization bypass by manipulating user-controlled keys.

Executive summary

A critical authorization bypass vulnerability in the Menulux Software Mobile App enables unauthenticated attackers to access restricted data, posing a significant risk to user privacy.

Vulnerability

This flaw, classified as CWE-639, allows an unauthenticated attacker to manipulate identifiers to bypass authorization checks. The vulnerability is remotely exploitable without user interaction and carries a CVSS score of 7.5, indicating a high risk of unauthorized data access.

Business impact

The ability to bypass authorization mechanisms can lead to the unauthorized exposure of sensitive user or business data managed within the application. Given the high CVSS score, this vulnerability represents a severe threat to data confidentiality and could result in significant regulatory and reputational damage if exploited.

Remediation

Immediate Action: Update the Menulux Software Mobile App to version 9.5.8 or later to incorporate the necessary security fixes.

Proactive Monitoring: Review application access logs for unusual patterns or access requests that deviate from standard user behavior.

Compensating Controls: Implement network-level access controls or a Web Application Firewall where applicable to filter suspicious traffic directed at the mobile backend services.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing the Menulux Software Mobile App must prioritize upgrading to version 9.5.8 immediately to eliminate this authorization bypass risk. Given the high impact on data confidentiality, failure to patch leaves the environment susceptible to unauthorized information disclosure.

More Menulux Software CVEs

Sources

Originally found and disclosed by Osman BARUTCU, per the CVE Program record.