CVE-2024-40069
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-40069 is a newly disclosed vulnerability affecting the Sourcecodester Online ID Generator System 1.0. This issue involves Stored Cross-Site Scripting (XSS) in the Users.php file, specifically in the 'save' function. The vulnerability lies in the POST parameters 'firstname' and 'lastname' where attackers can inject malicious scripts, posing a significant risk to users who visit the affected site. Successful exploitation could lead to unauthorized data access or theft, as well as potential site defacement or redirection to malicious websites. Users are strongly advised to upgrade or replace the affected system as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.