A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts.
History

Thu, 23 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-22T00:00:00.000Z

Updated: 2025-01-23T16:25:10.746Z

Reserved: 2025-01-09T00:00:00.000Z

Link: CVE-2024-56924

cve-icon Vulnrichment

Updated: 2025-01-23T16:25:03.591Z

cve-icon NVD

Status : Received

Published: 2025-01-22T21:15:09.987

Modified: 2025-01-23T17:15:16.710

Link: CVE-2024-56924

cve-icon Redhat

No data.