CVE-2024-12972: Akinsoft Octocloud
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft OctoCloud allows Cross-Site Scripting (XSS). This issue affects OctoCloud: from s1.09.01 before v1.11.01.
Affected products
- Akinsoft Octocloud: from s1.09.01, before v1.11.01 (fixed in v1.11.01)
Published 2025-09-02. Last modified 2026-06-17.