Impact
This vulnerability is an IDOR that allows a user-controlled key to bypass authorization checks in Menulux Software Inc.'s Mobile App. The flaw is described as a Software Integrity Attack, indicating that an attacker could potentially read, modify, or execute data and operations that should be protected. The CVSS score of 9.8 demonstrates a severe impact on confidentiality, integrity, and availability, with no authentication or additional mitigations reported in the description.
Affected Systems
Menulux Software Inc. Mobile App versions up to and including 12.05.2026 are affected.
Risk and Exploitability
Because this flaw is accessed via the mobile application, the likely attack vector is local or remote use of the app, possibly through crafted requests or malicious user input. The EPSS score is not available, and the vulnerability is not listed in KEV, yet the high CVSS indicates a significant risk if exploited. Without an official patch details, the risk remains high until remediation is applied.
OpenCVE Enrichment