Cross-Site Request Forgery Vulnerability in Fabian Ros/SourceCodester Simple E-Banking System
CVE-2025-13119
Key Information:
- Vendor
Fabian Ros
- Status
- Vendor
- CVE Published:
- 13 November 2025
Badges
What is CVE-2025-13119?
A vulnerability has been identified in the Simple E-Banking System by Fabian Ros, allowing remote attackers to execute unauthorized commands via cross-site request forgery. The flaw permits attackers to manipulate user sessions, potentially leading to forced withdrawals and other malicious actions without user consent. Swift action is recommended to mitigate the risks associated with this exploit, as it has already been published and may be utilized by malicious actors.
Affected Version(s)
Simple E-Banking System 1.0
Simple E-Banking System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
