Junglewise Threat Intelligence

CVE-2025-11024: Akilli Commerce E-Commerce Website SQL injection

CVE-2025-11024 · Severity: critical · CVSS 9.8 · Published 2026-05-14

Technologies: Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website. Vendors: Akilli Commerce Software Technologies Ltd. Co..

Executive brief

Akilli Commerce Software Technologies' e-commerce platform is vulnerable to a critical security flaw that allows unauthorized individuals to manipulate the underlying database. This software is used by businesses to manage online storefronts and customer transactions. An attacker could exploit this to steal sensitive customer data, modify product information, or disrupt the website's operations entirely.

Technical details

A Blind SQL Injection vulnerability (CWE-89) exists in the Akilli Commerce Software Technologies E-Commerce Website due to improper neutralization of special elements in SQL commands. The flaw is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N), allowing an attacker to send crafted queries to the database. By observing the application's response patterns, an attacker can extract sensitive information, modify records, or potentially gain full control over the database server. The issue is addressed in version 4.5.001.

Affected products

  • Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website before 4.5.001

Timeline

  • 2026-05-14: advisory: NVD and TR-CERT published the vulnerability details.

References

Related threats