
Proof-of-concept for a stored XSS vulnerability in Code Astro Internet Banking System 2.0.0, demonstrating session hijacking and client-side attacks via the name parameter in pages_account.php.
A Stored Cross-Site Scripting (XSS) vulnerability exists in Code Astro Internet Banking System 2.0.0 via the name parameter in /admin/pages_account.php. Malicious JavaScript code can be injected and stored in the system, executing whenever an admin views the affected page. This can lead to session hijacking and other client-side attacks.
name parameter in /admin/pages_account.php
name field and submit the form: //--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(98, 49, 116, 109, 52, 114));</SCRIPT>



Impact
Mitigation
References