Impact
A stored cross‑site scripting flaw exists in Akilli Ticaret Software Technologies Ltd.'s E‑Commerce Pack due to improper neutralization of user‑supplied input that is later displayed on web pages. The vulnerability allows an attacker to inject malicious JavaScript that is persisted in the database and rendered to other visitors in their browsers. This can be used to hijack user sessions, steal sensitive information, deface content, or serve additional malware, thereby compromising confidentiality, integrity, and availability of the application.
Affected Systems
Akilli Ticaret Software Technologies Ltd. E‑Commerce Pack versions starting at 4.5.001 and up to, but excluding, 4.6.001 are affected. Any installation running one of those releases without the vendor’s remediation is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of <1 % suggests a very low but non‑zero probability of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Attackers would likely have to submit malicious payloads through any input interface that stores data for later display, such as product descriptions or comments; once stored, the payload executes in the victim’s browser context, enabling credential theft or defacement. The risk is therefore moderate, with the main mitigation concern being the breadth of input points that could be abused.
OpenCVE Enrichment