Code Astro Internet Banking System
cpe:2.3:a:codeastro:internet_banking_system:*:*:*:*:*:*:*
- 2.0.0
A Cross-Site Request Forgery (CSRF) vulnerability exists in Code Astro Internet Banking System version 2.0.0. This vulnerability allows remote attackers to execute arbitrary JavaScript on the admin account page. The issue arises from inadequate validation of user requests, enabling attackers to manipulate admin users into executing harmful scripts. Exploitation could lead to unauthorized changes in account settings or the theft of sensitive user information.
Exploitation of this vulnerability could result in unauthorized actions being performed on behalf of an admin user, such as altering account details or compromising sensitive information.
To reproduce this vulnerability, log into the admin portal of Code Astro Internet Banking System 2.0.0. Navigate to the Accounts section and intercept the request using Burp Suite. After capturing the request, generate a CSRF proof of concept by modifying the request to include updates for the name and email fields. Once the request is modified, test it in the browser. The name and email fields will be changed successfully, demonstrating the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.