CVE-2025-29017: Malicious File Upload
Published Apr 10, 2025
·Updated
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profilepic parameter within pagesviewclient.php.
Affected Software
2 affected components
Code Astro Internet Banking System
Codeastro Internet Banking System=2.0.0
Event History
Apr 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29017?
CVE-2025-29017 has been classified as a critical Remote Code Execution vulnerability.
2
How do I fix CVE-2025-29017?
To mitigate CVE-2025-29017, ensure proper validation and sanitization of file uploads in the profile_pic parameter.
3
What systems are affected by CVE-2025-29017?
CVE-2025-29017 affects version 2.0.0 of the Code Astro Internet Banking System.
4
What type of attack can CVE-2025-29017 facilitate?
CVE-2025-29017 can facilitate Remote Code Execution attacks, allowing attackers to execute arbitrary code on the server.
5
Is there a patch available for CVE-2025-29017?
As of now, there is no specific patch announced for CVE-2025-29017, but users should apply security best practices to avoid exploitation.