Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-2636

Опубликовано: 19 мар. 2024
Источник: nvd
CVSS3: 9
EPSS Низкий

Описание

An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/config/espanol/update_password.jsp' file. Modifying the 'M4_NEW_PASSWORD' parameter, an attacker could store a malicious JSP file inside the file directory, to be executed the the file is loaded in the application.

EPSS

Процентиль: 26%
0.0009
Низкий

9 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9
github
почти 2 года назад

An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/config/espanol/update_password.jsp' file. Modifying the 'M4_NEW_PASSWORD' parameter, an attacker could store a malicious JSP file inside the file directory, to be executed the the file is loaded in the application.

EPSS

Процентиль: 26%
0.0009
Низкий

9 Critical

CVSS3

Дефекты

CWE-434