CVE-2024-40068
- EPSS 0.11%
- Veröffentlicht 16.04.2025 00:00:00
- Zuletzt bearbeitet 22.04.2025 17:00:11
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.
CVE-2024-40069
- EPSS 0.14%
- Veröffentlicht 16.04.2025 00:00:00
- Zuletzt bearbeitet 22.04.2025 17:00:04
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.
CVE-2024-40070
- EPSS 0.13%
- Veröffentlicht 16.04.2025 00:00:00
- Zuletzt bearbeitet 22.04.2025 16:59:56
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2024-40071
- EPSS 2.1%
- Veröffentlicht 16.04.2025 00:00:00
- Zuletzt bearbeitet 22.04.2025 16:59:46
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted ...
CVE-2024-40072
- EPSS 0.27%
- Veröffentlicht 16.04.2025 00:00:00
- Zuletzt bearbeitet 22.04.2025 16:59:32
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.
CVE-2024-40073
- EPSS 0.27%
- Veröffentlicht 16.04.2025 00:00:00
- Zuletzt bearbeitet 22.04.2025 16:59:14
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.
CVE-2024-40074
- EPSS 0.17%
- Veröffentlicht 16.04.2025 00:00:00
- Zuletzt bearbeitet 22.04.2025 16:58:19
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.