Junglewise Threat Intelligence

CVE-2024-12974: Akinsoft ProKuaför Cross-Site Scripting

CVE-2024-12974 · Severity: medium · CVSS 4.3 · Published 2025-09-02

Vendors: AKINSOFT.

Executive brief

Akinsoft ProKuaför, a management software for hair salons and beauty centers, contains a security vulnerability that could allow an attacker to inject malicious scripts into the application's web interface. If an administrative user interacts with a compromised page, the attacker could potentially perform unauthorized actions or steal session information. This could lead to unauthorized access to customer data or salon management functions.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Akinsoft ProKuaför versions s1.02.07 through v1.02.08. The flaw stems from improper neutralization of user-supplied input during the generation of web pages (CWE-79). An attacker with high privileges can exploit this over the network by injecting malicious scripts that execute in the context of another user's browser session, typically requiring some form of user interaction. Successful exploitation can lead to a limited loss of confidentiality, integrity, and availability. The issue is addressed in version v1.02.08.

Affected products

  • Akinsoft ProKuaför s1.02.07 to v1.02.08

Timeline

  • 2025-09-02: advisory: Initial NVD publication
  • 2026-01-06: other: Advisory record modified

References