Vulnerability Description
A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codeastro | Internet Banking System | 2.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/ipratheep/CVE-2024-56924ExploitThird Party Advisory
- https://github.com/ipratheep/CVE-2024-56924ExploitThird Party Advisory
FAQ
What is CVE-2024-56924?
CVE-2024-56924 is a vulnerability with a CVSS score of 7.3 (HIGH). A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially lea...
How severe is CVE-2024-56924?
CVE-2024-56924 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-56924?
Check the references section above for vendor advisories and patch information. Affected products include: Codeastro Internet Banking System.