CVE-2025-13479
IDOR in PosCube's QR Menu
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers. This issue affects QR Menu: through 21052026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-639 |
| Vendor | poscube hardware software and consulting ltd. |
| Product | qr menu |
| Published | May 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for poscube hardware software and consulting ltd. qr menu
Be the first to know when new high vulnerabilities affecting poscube hardware software and consulting ltd. qr menu are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
PosCube Hardware Software and Consulting Ltd. / QR Menu
0 ≤ 21052026
References
Credits
Ahmet Umut OĞURLU