Executive brief
Aksis Technology's Netty ERP, a software suite used for managing business operations and data, contains a critical security flaw. This vulnerability allows unauthorized individuals to manipulate the system's database over the internet. An attacker could potentially steal sensitive company information, modify financial records, or disrupt business operations entirely.
Technical details
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in Aksis Technology Inc. Netty ERP versions prior to V.1.1000. The flaw is caused by insufficient sanitization of user-supplied input before it is used in database queries. A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to the application. Successful exploitation allows the attacker to read, modify, or delete sensitive data within the backend database, and potentially gain full administrative control over the ERP environment. A patch is available in version V.1.1000.
Affected products
- Aksis Technology Inc. Netty ERP before V.1.1000
Timeline
- 2025-10-24: disclosed
- 2025-10-24: advisory