A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-53451 | A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/ipratheep/CVE-2024-56924 |
|
History
Mon, 04 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codeastro
Codeastro internet Banking System |
|
| CPEs | cpe:2.3:a:codeastro:internet_banking_system:2.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Codeastro
Codeastro internet Banking System |
Thu, 23 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Wed, 22 Jan 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-23T16:25:10.746Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-56924
Updated: 2025-01-23T16:25:03.591Z
Status : Analyzed
Published: 2025-01-22T21:15:09.987
Modified: 2025-08-04T15:08:25.273
Link: CVE-2024-56924
No data.
OpenCVE Enrichment
No data.
EUVD