Junglewise Threat Intelligence

CVE-2025-6919: Cats IT Aykome License Tracking System SQL injection

CVE-2025-6919 · Severity: critical · CVSS 9.8 · Published 2025-10-13

Executive brief

A critical security flaw has been identified in the Aykome License Tracking System, a software platform used for managing organizational licenses. This vulnerability allows an unauthorized person to gain full access to the underlying database over the internet. An attacker could steal sensitive licensing data, modify records, or disrupt the system's availability, potentially leading to significant operational and data integrity risks.

Technical details

The Aykome License Tracking System contains an SQL injection vulnerability (CWE-89) due to improper neutralization of special elements in SQL commands. The flaw is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can exploit this to execute arbitrary SQL queries, leading to the full compromise of confidentiality, integrity, and availability of the database. The issue affects all versions of the software released before October 6, 2025. Users are advised to update to the latest version provided by the vendor.

Affected products

  • Cats Information Technology Software Development Technologies Aykome License Tracking System Versions prior to 2025-10-06

Timeline

  • 2025-10-13: advisory: Initial disclosure by TR-CERT (USOM)
  • 2025-10-06: patched: Vendor released a version addressing the issue

References