Impact
The vulnerability in Menulux Portal is a missing authorization control that allows unauthorized users to access critical POS management functions. Because access‑control lists do not properly constrain these functions, an attacker who obtains valid credentials or exploits a local session could perform actions such as modifying inventory, pricing, or transaction processing without approval. This could lead to financial loss, data tampering, or unauthorized configuration changes, directly impacting the integrity and availability of point‑of‑sale operations.
Affected Systems
The issue is present in all versions of Menulux Portal released before the build identifier 20260903211448. The affected vendor is Menulux Software Inc., and the product is Menulux Portal, a web‑based management interface used by retailers to control POS devices and back‑office functions.
Risk and Exploitability
The CVSS score of 4.3 indicates a lower severity compared to remote code execution vulnerabilities, but the lack of proper ACL enforcement still poses a significant operational risk. EPSS is unavailable, so current exploitation probability cannot be measured; however, the vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits yet. Likely attack vectors involve authenticated users or compromised accounts within the portal, with the attacker leveraging the exposed function calls directly through the web interface. In the absence of a patch, the risk primarily lies in internal or privileged users abusing the system.
OpenCVE Enrichment