Impact
This vulnerability allows the Menulux Portal to store user passwords in plaintext, enabling an attacker with access to the underlying storage to recover account credentials and immediately impersonate users, thereby compromising confidentiality and potentially availability of services.
Affected Systems
Menulux Portal provided by Menulux Software Inc. is affected by this flaw. All releases before the build identifier 20260903211448 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation typically requires local access to the portal's database or file system, where the plaintext credentials can be retrieved. If the database is exposed over a network, remote exploitation may also be possible, but the description does not confirm such exposure.
OpenCVE Enrichment