Impact
An observable response discrepancy vulnerability in Menulux Portal allows an attacker to discover valid usernames, enabling account discovery and facilitating subsequent credential attacks. The flaw is related to improper resource identification and can expose user existence via differing responses.
Affected Systems
The vulnerability affects Menulux Software Inc.'s Menulux Portal versions prior to 20260903211448, which are deployed in affected environments and have not yet applied the referenced update.
Risk and Exploitability
With a CVSS score of 7.5, this issue is considered high risk, and it is not currently listed in CISA KEV. The EPSS score is not available, but the attack vector is inferred to be remote, exploiting the web interface by sending crafted requests to elicit differing responses based on user validity. If exploited, the attacker could enumerate legitimate accounts and potentially launch phishing or credential stuffing attacks.
OpenCVE Enrichment