CVE-2024-40071
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 16, 2025
Updated: Apr 22, 2025
CWE ID 434
Summary
CVE-2024-40071: A critical vulnerability was identified in the Sourcecodester Online ID Generator System 1.0. This issue permits attackers to upload arbitrary files to the id_generator/classes/SystemSettings.php?f=update_settings endpoint, potentially leading to the execution of malicious PHP code, posing a significant risk to system integrity and security. Attackers can exploit this vulnerability to gain unauthorized access or modify sensitive data. Users are strongly advised to update the system as soon as a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.