Junglewise Threat Intelligence

CVE-2025-8079: Akıllı Ticaret Smart Trade E-Commerce Reflected XSS

CVE-2025-8079 · Severity: medium · CVSS 4.6 · Published 2025-09-22

Executive brief

Akıllı Ticaret Smart Trade E-Commerce, a platform used for managing online retail stores, contains a security vulnerability that allows for reflected cross-site scripting. An attacker could use this flaw to execute malicious scripts in the browser of a logged-in user, potentially leading to unauthorized actions or the theft of session information. This could compromise the integrity of the store management interface or lead to the exposure of customer-related data handled by the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Akıllı Ticaret Smart Trade E-Commerce versions prior to 4.5.0.0.1. The flaw is caused by the application's failure to properly neutralize user-supplied input before including it in dynamically generated web pages (CWE-79). An attacker with low-privileged network access can exploit this by tricking a victim into interacting with a specially crafted link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to hijack sessions or perform unauthorized actions. The issue is addressed in version 4.5.0.0.1.

Affected products

  • Akıllı Ticaret Software Technologies Ltd. Co. Smart Trade E-Commerce before 4.5.0.0.1

Timeline

  • 2025-09-22: advisory: Initial publication of the CVE record.

References