A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sitetest/english/dumpenv.jsp' is vulnerable to XSS attack by 'lang' query, i.e. '/sitetest/english/dumpenv.jsp?snoop=yes&lang=%27%3Cimg%20src/onerror=alert(1)%3E&params'.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-27582 A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sitetest/english/dumpenv.jsp' is vulnerable to XSS attack by 'lang' query, i.e. '/sitetest/english/dumpenv.jsp?snoop=yes&lang=%27%3Cimg%20src/onerror=alert(1)%3E&params'.
Fixes

Solution

The Meta4 HR system administrator should remove the following pages from the web servers facing the Internet: From M4WebServices: The folder "sitetest" (containing the dumpenv.jsp page) From M4Gateway: The page dump.jsp In future releases of Cegid Meta4 HR, these pages will be removed from the distribution since they do not offer real functionality.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T19:18:48.243Z

Reserved: 2024-03-19T06:44:58.359Z

Link: CVE-2024-2633

cve-icon Vulnrichment

Updated: 2024-08-01T19:18:48.243Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-19T12:15:09.530

Modified: 2024-11-21T09:10:10.873

Link: CVE-2024-2633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses