First published: Thu Mar 20 2025(Updated: )
A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Martmbithi iBanking | ||
Martmbithi iBanking | =2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29412 is considered a high severity vulnerability due to its potential for allowing cross-site scripting attacks.
To fix CVE-2025-29412, you should validate and sanitize user inputs in the Client Profile Update section before processing them.
CVE-2025-29412 allows attackers to execute arbitrary web scripts or HTML, leading to potential phishing or session hijacking attacks.
Yes, if you are using Mart Developers iBanking version 2.0.0, your application is vulnerable to CVE-2025-29412.
Exploiting CVE-2025-29412 can lead to unauthorized access, data theft, and manipulation of user sessions.