First published: Wed Apr 16 2025(Updated: )
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sourcecodester Online ID Generator System | ||
Oretnom23 Online Id Generator System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40069 has a moderate severity level due to its potential for Stored Cross Site Scripting (XSS) attacks.
To fix CVE-2024-40069, sanitize and validate user inputs for the 'firstname' and 'lastname' parameters in the save function.
Exploiting CVE-2024-40069 can lead to unauthorized code execution and the delivery of malicious payloads to users.
CVE-2024-40069 affects the Users.php file in the ID generator classes of Sourcecodester Online ID Generator System.
CVE-2024-40069 specifically impacts version 1.0 of Sourcecodester Online ID Generator System.