PT-2025-3349 · Unknown · Codeastro Internet Banking System
Ipratheep
·
Published
2025-01-22
·
Updated
2025-08-04
·
CVE-2024-56924
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Code Astro Internet banking system version 2.0.0
Description
A Cross Site Request Forgery (CSRF) vulnerability exists in Code Astro Internet banking system version 2.0.0. This allows remote attackers to execute arbitrary JavaScript on the admin page (
pages account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. The vulnerability occurs due to improper validation of user requests, enabling attackers to exploit the system by tricking the admin user into executing malicious scripts.Recommendations
Code Astro Internet banking system version 2.0.0: Implement robust CSRF protection mechanisms, such as synchronizer tokens, to validate user requests and prevent unauthorized actions. Ensure all user inputs are properly validated and sanitized before processing.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codeastro Internet Banking System