CVE-2024-40071

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 22, 2025
CWE ID 434

Summary

CVE-2024-40071: A critical vulnerability was identified in the Sourcecodester Online ID Generator System 1.0. This issue permits attackers to upload arbitrary files to the id_generator/classes/SystemSettings.php?f=update_settings endpoint, potentially leading to the execution of malicious PHP code, posing a significant risk to system integrity and security. Attackers can exploit this vulnerability to gain unauthorized access or modify sensitive data. Users are strongly advised to update the system as soon as a patch is available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share