Executive brief
Akilli Ticaret's E-Commerce Pack, a platform for building online stores, contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into web pages. An attacker can exploit this to steal customer data, compromise user sessions, or redirect customers to fraudulent sites, directly damaging customer trust and business operations.
Technical details
The vulnerability is a stored XSS flaw in the web page generation logic of E-Commerce Pack versions 4.5.001 through before 4.6.001, where user input is not properly neutralized before being rendered in the HTML response. An attacker can inject malicious JavaScript through input fields that are stored in the application's database and served to subsequent users, allowing arbitrary script execution in the browser context of any visitor to the affected page. No authentication is required to exploit this issue, making it a significant risk for e-commerce platforms. A patch is available in version 4.6.001 or later.
Affected products
- Akilli Ticaret Software Technologies E-Commerce Pack 4.5.001 to before 4.6.001
Timeline
- 2026-08-28: disclosed