CVE-2024-0781

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 22, 2024
Updated: May 17, 2024
CWE ID 601

Summary

CVE-2024-0781 is a newly identified vulnerability affecting the CodeAstro Internet Banking System 1.0. It lies in the file pages_client_signup.php, specifically an unknown part of it. This issue can be exploited through manipulation of the Client Full Name argument with the input <meta http-equiv="refresh" content="0; url=https://vulnerable-website.com" />. The result is an open redirect, allowing attackers to initiate the attack remotely. Public disclosure of the exploit increases the risk, assigning it the identifier VDB-251697.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share