CVE-2024-40074

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 22, 2025
CWE ID 79

Summary

CVE-2024-40074 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Sourcecodester Online ID Generator System 1.0. The weakness lies within the 'id_generator/classes/SystemSettings.php?f=update_settings' page, specifically in the 'short_name' POST parameter. An attacker can inject malicious scripts into the system by manipulating this parameter, leading to potential data theft or unauthorized account access. This issue poses a significant risk to users who interact with the affected application, making it essential for prompt patching or mitigation measures.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share