Vulnerabilities (CVE)

Filtered by vendor Oretnom23 Subscribe
Filtered by product Online Id Generator System
Total 7 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-40068 1 Oretnom23 1 Online Id Generator System 2025-04-22 N/A 5.9 MEDIUM
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.
CVE-2024-40069 1 Oretnom23 1 Online Id Generator System 2025-04-22 N/A 5.4 MEDIUM
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.
CVE-2024-40070 1 Oretnom23 1 Online Id Generator System 2025-04-22 N/A 5.1 MEDIUM
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2024-40071 1 Oretnom23 1 Online Id Generator System 2025-04-22 N/A 9.8 CRITICAL
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2024-40072 1 Oretnom23 1 Online Id Generator System 2025-04-22 N/A 9.8 CRITICAL
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.
CVE-2024-40073 1 Oretnom23 1 Online Id Generator System 2025-04-22 N/A 9.8 CRITICAL
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.
CVE-2024-40074 1 Oretnom23 1 Online Id Generator System 2025-04-22 N/A 4.8 MEDIUM
Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.