Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gp7-8ggq-x9c3

Опубликовано: 19 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/config/espanol/update_password.jsp' file. Modifying the 'M4_NEW_PASSWORD' parameter, an attacker could store a malicious JSP file inside the file directory, to be executed the the file is loaded in the application.

An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/config/espanol/update_password.jsp' file. Modifying the 'M4_NEW_PASSWORD' parameter, an attacker could store a malicious JSP file inside the file directory, to be executed the the file is loaded in the application.

EPSS

Процентиль: 26%
0.0009
Низкий

9 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9
nvd
почти 2 года назад

An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/config/espanol/update_password.jsp' file. Modifying the 'M4_NEW_PASSWORD' parameter, an attacker could store a malicious JSP file inside the file directory, to be executed the the file is loaded in the application.

EPSS

Процентиль: 26%
0.0009
Низкий

9 Critical

CVSS3

Дефекты

CWE-434