CVE-2025-8589: Reflected XSS in AKCE Software's SKSPro
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows Reflected XSS.
This issue affects SKSPro: through 07012026.
Security readout for executives and security teams
Plain-English summary
CVE-2025-8589 is a reflected cross-site scripting flaw in AKCE Software SKSPro. An attacker could trick a user into interacting with unsafe content generated by SKSPro. The CVE rates it high, with potential confidentiality, integrity, and availability impact.
Executive priority
Treat this as a high-priority product exposure if SKSPro is in use. The business urgency is strongest for externally reachable deployments, but evidence is incomplete on exploitation and vendor fixes.
Technical view
The issue is CWE-79 improper input neutralization during web page generation. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H. Sources state SKSPro is affected through version string 07012026, but do not name a fixed release.
Likely exposure
Exposure is likely limited to organizations running AKCE Software SKSPro, especially deployments reachable by employees, customers, or partners through a browser. The sources do not identify CPEs or deployment architecture.
Exploitation context
The CVE requires user interaction and network reachability. The source bundle does not show CISA KEV listing or cited evidence of active exploitation, public exploit code, or observed campaigns.
Researcher notes
The record has inconsistent affected-version metadata: the description says through 07012026, while the affected array lists version 0 with defaultStatus unaffected. Validate against vendor or advisory text before scoping broadly.
Mitigation direction
Check AKCE Software and Turkish government advisory guidance for a fixed SKSPro release.
Restrict external access to SKSPro until vendor guidance is confirmed.
Prioritize patching or vendor-approved remediation for internet-facing SKSPro instances.
Use web application controls to reduce script injection risk where appropriate.
Monitor SKSPro access logs for suspicious crafted requests.
Validation and detection
Inventory all SKSPro deployments and installed version strings.
Confirm whether any deployment is through 07012026.
Review vendor or government advisory updates for corrected versions.
Run safe XSS validation using approved internal testing procedures.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-79 · source CWE mapping
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.