A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/ipratheep/CVE-2024-56924 | Exploit Third Party Advisory | 
| https://github.com/ipratheep/CVE-2024-56924 | Exploit Third Party Advisory | 
Configurations
                    History
                    04 Aug 2025, 15:08
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:codeastro:internet_banking_system:2.0.0:*:*:*:*:*:*:* | |
| References | () https://github.com/ipratheep/CVE-2024-56924 - Exploit, Third Party Advisory | |
| First Time | Codeastro internet Banking System Codeastro | 
23 Jan 2025, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-352 | |
| References | () https://github.com/ipratheep/CVE-2024-56924 - | |
| Summary | 
 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.3 | 
22 Jan 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-01-22 21:15
Updated : 2025-08-04 15:08
NVD link : CVE-2024-56924
Mitre link : CVE-2024-56924
CVE.ORG link : CVE-2024-56924
JSON object : View
Products Affected
                codeastro
- internet_banking_system
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
