PT-2025-16787 · Sourcecodester · Sourcecodester Online Id Generator System

Published

2025-04-16

·

Updated

2025-04-20

·

CVE-2024-40070

CVSS v3.1

5.1

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester Online ID Generator System version 1.0
Description The issue allows attackers to execute arbitrary code via a crafted PHP file, exploiting an arbitrary file upload vulnerability. This is achieved through the id generator/classes/Users.php?f=save endpoint.
Recommendations For version 1.0, consider disabling the file upload functionality in the id generator/classes/Users.php?f=save endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using this endpoint with untrusted input until the issue is resolved.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-40070

Affected Products

Sourcecodester Online Id Generator System