CVE-2025-29017: Codeastro Internet Banking System

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.

Affected products

  • Codeastro Internet Banking System: version 2.0.0 only

Published 2025-04-10. Last modified 2026-06-17.