Junglewise Threat Intelligence

CVE-2025-6577: Akilli Commerce Software Technologies E-Commerce Website SQL injection

CVE-2025-6577 · Severity: critical · CVSS 9.8 · Published 2026-05-12

Technologies: Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website. Vendors: Akilli Commerce Software Technologies Ltd. Co..

Executive brief

Akilli Commerce Software Technologies' e-commerce platform is vulnerable to a critical security flaw that allows attackers to manipulate the underlying database. This software is used to power online storefronts and manage customer transactions. An exploit could allow an unauthorized person to steal sensitive customer data, modify product pricing, or disrupt the entire online shopping service.

Technical details

An SQL injection vulnerability (CWE-89) exists in the Akilli Commerce Software Technologies E-Commerce Website due to improper neutralization of special elements used in SQL commands. The flaw is exploitable over the network without authentication or user interaction. A remote attacker can leverage this vulnerability to execute arbitrary SQL queries against the backend database, potentially leading to full data exfiltration, unauthorized data modification, or administrative bypass. The issue is resolved in version 4.5.001.

Affected products

  • Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website before 4.5.001

Timeline

  • 2026-05-12: advisory: Initial publication of CVE-2025-6577 by TR-CERT
  • 2026-05-12: disclosed

References

Related threats