PT-2024-15809 · Unknown · Codeastro Internet Banking System

Mohammed Aashique

·

Published

2024-01-21

·

Updated

2024-05-17

·

CVE-2024-0773

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CodeAstro Internet Banking System version 1.0
Description A problematic vulnerability was found in the CodeAstro Internet Banking System, affecting an unknown functionality of the file pages client signup.php. The manipulation of the Client Full Name argument leads to cross-site scripting. The attack can be launched remotely.
Recommendations For CodeAstro Internet Banking System version 1.0, consider restricting access to the pages client signup.php file until a patch is available. As a temporary workaround, avoid using the Client Full Name argument in the affected functionality to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-0773

Affected Products

Codeastro Internet Banking System