CVE-2025-13474: IDOR in Menulux Software's Mobile App
Published Dec 16, 2025
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Menulux Software Inc. Mobile App allows Exploitation of Trusted Identifiers.
This issue affects Mobile App: before 9.5.8.
Affected Software
1 affected component
Menulux Software Menulux Mobile App<9.5.8
Event History
Dec 16, 2025
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-13474?
CVE-2025-13474 has been classified with a high severity due to its potential for exploitation through authorization bypass.
2
How do I fix CVE-2025-13474?
To fix CVE-2025-13474, update the Menulux Software Mobile App to version 9.5.8 or later.
3
What platforms are affected by CVE-2025-13474?
CVE-2025-13474 affects the Menulux Software Mobile App versions prior to 9.5.8.
4
What type of vulnerability is CVE-2025-13474?
CVE-2025-13474 is an authorization bypass vulnerability that allows exploitation of trusted identifiers.
5
Who is the vendor for CVE-2025-13474?
The vendor for CVE-2025-13474 is Menulux Software Inc.