PT-2023-32267 · Unknown · Codeastro Internet Banking System
Published
2023-10-22
·
Updated
2024-06-05
·
CVE-2023-5694
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CodeAstro Internet Banking System version 1.0
Description
A vulnerability was found in the CodeAstro Internet Banking System, classified as problematic. It affects an unknown function of the file pages system settings.php. The manipulation of the argument
sys name with the input <ScRiPt >alert(991)</ScRiPt> leads to cross-site scripting. This issue can be exploited remotely.Recommendations
For CodeAstro Internet Banking System version 1.0, consider disabling the unknown function of the file pages system settings.php until a patch is available. Restrict access to the
sys name argument to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codeastro Internet Banking System