CVE-2025-29018: Codeastro Internet Banking System
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0.
Affected products
- Codeastro Internet Banking System: version 2.0.0 only
Published 2025-04-09. Last modified 2026-06-17.