PT-2024-22547 · Unit4 · Unit4 Financials

Published

2024-03-19

·

Updated

2024-07-03

·

CVE-2024-28734

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Unit4 Financials by Coda versions prior to 2023Q4
Description The issue allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter. This enables the attacker to potentially escalate privileges.
Recommendations For versions prior to 2023Q4, consider disabling the use of the cols parameter in GET requests until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-28734

Affected Products

Unit4 Financials