SQL Injection Vulnerability in Akilli Commerce E-Commerce Software
CVE-2025-6577

9.8CRITICAL

What is CVE-2025-6577?

An improper handling of special characters in SQL commands has been identified in the Akilli Commerce E-Commerce Website. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized access to sensitive data. The issue affects all versions of the E-Commerce Website prior to 4.5.001. It is crucial for users of this software to implement security measures to protect their databases from exploitation.

Affected Version(s)

E-Commerce Website 0 < 4.5.001

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sevban Alp DĂ–NMEZ
.