Junglewise Threat Intelligence

CVE-2024-12973: Akinsoft OctoCloud origin validation error in web interface

CVE-2024-12973 · Severity: medium · CVSS 4.7 · Published 2025-09-02

Technologies: AKINSOFT OctoCloud. Vendors: AKINSOFT.

Executive brief

Akinsoft OctoCloud, a business management and cloud ERP solution, contains a security flaw in how it validates the origin of web requests. An attacker with high-level administrative privileges could exploit this to manipulate server responses or access restricted files through forceful browsing. This could lead to unauthorized access to sensitive business data or minor disruptions in service operations.

Technical details

An Origin Validation Error (CWE-346) exists in Akinsoft OctoCloud versions s1.09.01 through v1.11.01. The vulnerability allows for HTTP Response Splitting and Forceful Browsing (CAPEC-87) due to insufficient validation of request origins. An attacker with high privileges (PR:H) can exploit this over the network to bypass certain security constraints, potentially leading to unauthorized information disclosure or data modification. The issue is addressed in version v1.11.01.

Affected products

  • Akinsoft OctoCloud from s1.09.01 before v1.11.01

Timeline

  • 2025-09-02: disclosed
  • 2025-09-02: advisory

References

Related threats