CVE-2024-40072

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 22, 2025
CWE ID 89

Summary

CVE-2024-40072 is a newly discovered SQL injection vulnerability affecting the Sourcecodester Online ID Generator System 1.0. An attacker can exploit this flaw by inputting malicious SQL queries through the id parameter in the URL, specifically in the id_generator/admin/?page=generate/index&id=1 endpoint. Successful exploitation could lead to unauthorized data access or modification within the affected database. System administrators are strongly advised to patch or upgrade the system as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share