Executive brief
AKIN Software's e-Commerce platform, used for managing online retail stores, contains a security flaw that allows attackers to inject malicious scripts into web pages. If a user clicks a specially crafted link, an attacker could potentially steal session cookies, impersonate the user, or modify the content of the page. This could lead to unauthorized access to customer accounts or the theft of sensitive information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in AKIN Software e-Commerce versions prior to 1.25.01.06. The application fails to properly neutralize user-supplied input during the generation of web pages, allowing an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's browser. This is achieved by tricking a user into clicking a malicious link (Reflected XSS). Successful exploitation can lead to session hijacking, unauthorized data access, or website defacement. The issue is addressed in version 1.25.01.06.
Affected products
- AKIN Software Computer Import Export Industry and Trade Ltd. e-Commerce before 1.25.01.06
Timeline
- 2026-06-23: disclosed: Initial publication of the CVE record.
- 2026-06-23: advisory: Advisory published by TR-CERT.