Executive brief
AKCE SKSPro is a software solution used for corporate resource or process management. A security flaw in this product allows attackers to perform reflected cross-site scripting (XSS) attacks. If an employee clicks a malicious link, an attacker could execute unauthorized scripts in their browser, potentially leading to session hijacking, data theft, or unauthorized actions performed on behalf of the user.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in AKCE Software Technology SKSPro through version 07012026. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into visiting a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can be used to steal session cookies or manipulate page content. The vulnerability is tracked as CVE-2025-8589 and has been assigned a CVSS v3.1 base score of 7.6.
Affected products
- AKCE Software Technology R&D Industry and Trade Inc. SKSPro through 07012026
Timeline
- 2026-02-03: disclosed: Initial publication of the CVE record