CVE-2024-40070

CVSS 3.1 Score 5.1 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 22, 2025
CWE ID 77

Summary

CVE-2024-40070 is a newly discovered vulnerability affecting the Sourcecodester Online ID Generator System 1.0. This issue involves an arbitrary file upload vulnerability, specifically located in the Users.php file within the id_generator/classes directory. Attackers can exploit this flaw by uploading a maliciously crafted PHP file, which grants them the ability to execute arbitrary code on the affected system. Successful exploitation of this vulnerability can lead to serious security consequences, including unauthorized access or data breaches. System administrators are strongly advised to patch the vulnerability promptly to prevent potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share