CVE-2025-29411: Martmbithi Ibanking
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Affected products
- Martmbithi Ibanking: version 2.0.0 only
Published 2025-03-20. Last modified 2026-06-17.