Executive brief
Akilli Commerce Software Technologies' e-commerce platform is vulnerable to a critical security flaw that allows unauthorized individuals to manipulate the underlying database. This software is used by businesses to manage online storefronts and customer transactions. An attacker could exploit this to steal sensitive customer data, modify product information, or disrupt the website's operations entirely.
Technical details
A Blind SQL Injection vulnerability (CWE-89) exists in the Akilli Commerce Software Technologies E-Commerce Website due to improper neutralization of special elements in SQL commands. The flaw is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N), allowing an attacker to send crafted queries to the database. By observing the application's response patterns, an attacker can extract sensitive information, modify records, or potentially gain full control over the database server. The issue is addressed in version 4.5.001.
Affected products
- Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website before 4.5.001
Timeline
- 2026-05-14: advisory: NVD and TR-CERT published the vulnerability details.