First published: Thu Mar 20 2025(Updated: )
An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Martmbithi iBanking | ||
Martmbithi iBanking | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29411 is considered critical due to its potential for arbitrary code execution via an unauthenticated arbitrary file upload.
To mitigate CVE-2025-29411, ensure that file uploads are strictly validated and restrict the types of files that can be uploaded.
CVE-2025-29411 affects Mart Developers iBanking version 2.0.0.
CVE-2025-29411 is an arbitrary file upload vulnerability allowing attackers to execute arbitrary code.
Exploiting CVE-2025-29411 could allow an attacker to execute malicious code on the server, potentially leading to full system compromise.