First published: Wed Apr 16 2025(Updated: )
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sourcecodester Online ID Generator System | ||
Oretnom23 Online Id Generator System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40074 is considered a high-severity vulnerability due to its potential for Stored Cross Site Scripting (XSS) exploitation.
To fix CVE-2024-40074, apply input validation and output encoding to the 'short_name' POST parameter in the affected system.
CVE-2024-40074 affects Sourcecodester Online ID Generator System version 1.0.
CVE-2024-40074 is a Stored Cross Site Scripting (XSS) vulnerability.
The point of vulnerability for CVE-2024-40074 is in the 'short_name' POST parameter within the update settings functionality.