PT-2024-21364 · Cegid · Cegid Meta4 Hr

Jesús Antón

·

Published

2024-03-19

·

Updated

2024-03-19

·

CVE-2024-2635

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Cegid Meta4 HR (affected versions not specified)
Description The configuration pages in Cegid Meta4 HR are not intended to be placed on an Internet-facing web server, as they expose file paths to the client, who can be an attacker. These pages do not offer product functionality and will be dismissed from future releases.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2635

Affected Products

Cegid Meta4 Hr