Impact
The vulnerability is a missing authorization flaw that allows an attacker to invoke critical POS operations without proper access control. Because the flaw is not limited to a single function, a compromised user or an external threat could gain access to functions that should be protected by ACLs, potentially leading to financial loss, data tampering, or disruption of point‑of‑sale operations.
Affected Systems
Gastromenum Ticket and QR Menu System installed on any system before 2026.08.31 is affected. The flaw is present in versions older than the 2026.08.31 release, and the vendor has not provided a fix or workaround for these versions.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, so the current exploit probability is uncertain. The likely attack vector is inferred to be through the web or POS interface where the ACLs are bypassed; however, the exact conditions for exploitation are not fully detailed in the public description.
OpenCVE Enrichment