PatchSiren cyber security CVE debrief
CVE-2025-7015 Akın Software Computer Import Export Industry and Trade Ltd. CVE debrief
A Session Fixation vulnerability was discovered in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu before version s1.05.12. This issue, tracked as CVE-2025-7015, has a CVSS score of 5.7 and is classified as MEDIUM severity. The vulnerability allows for Session Fixation attacks, which can occur when an attacker fixes the session ID in a user's browser, potentially leading to unauthorized access to the user's session.
- Vendor
- Akın Software Computer Import Export Industry and Trade Ltd.
- Product
- QR Menu
- CVSS
- MEDIUM 5.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-29
- Original CVE updated
- 2026-06-05
- Advisory published
- 2026-01-29
- Advisory updated
- 2026-06-05
Who should care
Administrators and users of Akın Software Computer Import Export Industry and Trade Ltd. QR Menu before version s1.05.12 should apply the necessary updates to mitigate this vulnerability.
Technical summary
The CVE-2025-7015 vulnerability affects QR Menu by Akın Software, specifically versions before s1.05.12. It is categorized under CWE-384, which pertains to Session Fixation vulnerabilities. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N, indicating that the attack vector is Network, Attack Complexity is Low, Privileges Required is Low, User Interaction is Required, Scope is Unchanged, Confidentiality impact is High, Integrity impact is None, and Availability impact is None.
Defensive priority
MEDIUM
Recommended defensive actions
- Update QR Menu to version s1.05.12 or later.
- Review and monitor user sessions for any suspicious activity.
- Implement additional security measures to protect against session fixation attacks.
Evidence notes
Evidence for this CVE comes from the National Vulnerability Database (NVD) and other official sources.
Official resources
-
CVE-2025-7015 CVE record
CVE.org
-
CVE-2025-7015 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
CVE-2025-7015 was published on 2026-01-29T12:16:30.057Z and modified on 2026-06-05T15:16:43.623Z.