Executive brief
Akilli Commerce Software Technologies' e-commerce platform is vulnerable to a critical security flaw that allows attackers to manipulate the underlying database. This software is used to power online storefronts and manage customer transactions. An exploit could allow an unauthorized person to steal sensitive customer data, modify product pricing, or disrupt the entire online shopping service.
Technical details
An SQL injection vulnerability (CWE-89) exists in the Akilli Commerce Software Technologies E-Commerce Website due to improper neutralization of special elements used in SQL commands. The flaw is exploitable over the network without authentication or user interaction. A remote attacker can leverage this vulnerability to execute arbitrary SQL queries against the backend database, potentially leading to full data exfiltration, unauthorized data modification, or administrative bypass. The issue is resolved in version 4.5.001.
Affected products
- Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website before 4.5.001
Timeline
- 2026-05-12: advisory: Initial publication of CVE-2025-6577 by TR-CERT
- 2026-05-12: disclosed