PT-2025-15988 · Unknown · Codeastro Internet Banking System

B1Tm4R

·

Published

2025-04-10

·

Updated

2025-07-28

·

CVE-2025-29017

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Code Astro Internet Banking System version 2.0.0
Description A Remote Code Execution (RCE) vulnerability exists due to improper file upload validation in the profile pic parameter within pages view client.php.
Recommendations Code Astro Internet Banking System version 2.0.0: Address the improper file upload validation in the profile pic parameter within the pages view client.php file.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-29017

Affected Products

Codeastro Internet Banking System