Junglewise Threat Intelligence

CVE-2024-12972: Akinsoft OctoCloud Cross-Site Scripting

CVE-2024-12972 · Severity: medium · CVSS 4.3 · Published 2025-09-02

Technologies: AKINSOFT OctoCloud. Vendors: AKINSOFT.

Executive brief

Akinsoft OctoCloud, a business management and accounting software, contains a security vulnerability that could allow an attacker to inject malicious scripts into the web interface. If a legitimate user interacts with the affected part of the application, the attacker could potentially steal session information or perform unauthorized actions on behalf of that user. This risk is primarily relevant to internal operations and data integrity within the management platform.

Technical details

Akinsoft OctoCloud versions s1.09.01 through v1.11.01 are vulnerable to a Cross-Site Scripting (XSS) flaw categorized under CWE-79. The vulnerability stems from the application's failure to properly sanitize user-supplied input before rendering it in the web interface. An attacker with high privileges (PR:H) can exploit this by injecting malicious scripts that execute in the context of another user's browser session when they view the affected page. While the attack requires network access and some user interaction, it can lead to unauthorized access to sensitive session tokens or the manipulation of page content. The issue is addressed in version v1.11.01.

Affected products

  • Akinsoft OctoCloud s1.09.01 to v1.11.01

Timeline

  • 2025-09-02: disclosed: Initial publication of the vulnerability advisory.
  • 2025-09-02: advisory: Advisory published by the Computer Emergency Response Team of the Republic of Turkey (USOM).

References

Related threats