CVE-2024-40069: XSS
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via idgenerator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40069?
CVE-2024-40069 has a moderate severity level due to its potential for Stored Cross Site Scripting (XSS) attacks.
How do I fix CVE-2024-40069?
To fix CVE-2024-40069, sanitize and validate user inputs for the 'firstname' and 'lastname' parameters in the save function.
What are the consequences of exploiting CVE-2024-40069?
Exploiting CVE-2024-40069 can lead to unauthorized code execution and the delivery of malicious payloads to users.
Which components of Sourcecodester Online ID Generator System are affected by CVE-2024-40069?
CVE-2024-40069 affects the Users.php file in the ID generator classes of Sourcecodester Online ID Generator System.
Is CVE-2024-40069 applicable to all versions of Sourcecodester Online ID Generator System?
CVE-2024-40069 specifically impacts version 1.0 of Sourcecodester Online ID Generator System.