PT-2024-21368 · Cegid · Cegid Meta4 Hr

Jesús Antón

·

Published

2024-03-19

·

Updated

2024-03-19

·

CVE-2024-2636

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cegid Meta4 HR (affected versions not specified)
Description An Unrestricted Upload of File issue allows an attacker to upload malicious files to the server via the "/config/espanol/update password.jsp" file. By modifying the M4 NEW PASSWORD parameter, an attacker could store a malicious JSP file inside the file directory, which would be executed when the file is loaded in the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-2636

Affected Products

Cegid Meta4 Hr