CVE-2024-40074
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-40074 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Sourcecodester Online ID Generator System 1.0. The weakness lies within the 'id_generator/classes/SystemSettings.php?f=update_settings' page, specifically in the 'short_name' POST parameter. An attacker can inject malicious scripts into the system by manipulating this parameter, leading to potential data theft or unauthorized account access. This issue poses a significant risk to users who interact with the affected application, making it essential for prompt patching or mitigation measures.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.