CVE-2024-40069

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 22, 2025
CWE ID 79

Summary

CVE-2024-40069 is a newly disclosed vulnerability affecting the Sourcecodester Online ID Generator System 1.0. This issue involves Stored Cross-Site Scripting (XSS) in the Users.php file, specifically in the 'save' function. The vulnerability lies in the POST parameters 'firstname' and 'lastname' where attackers can inject malicious scripts, posing a significant risk to users who visit the affected site. Successful exploitation could lead to unauthorized data access or theft, as well as potential site defacement or redirection to malicious websites. Users are strongly advised to upgrade or replace the affected system as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share