Description
A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sse_generico/generico_login.jsp' is vulnerable to XSS attack via 'lang' query, i.e. '/sse_generico/generico_login.jsp?lang=%27%3balert(%27BLEUSS%27)%2f%2f&params='.
Published: 2024-03-19
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Any product with all fixes applied after 2013 is not vulnerable to this XSS.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-27583 A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sse_generico/generico_login.jsp' is vulnerable to XSS attack via 'lang' query, i.e. '/sse_generico/generico_login.jsp?lang=%27%3balert(%27BLEUSS%27)%2f%2f&params='.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T19:18:47.903Z

Reserved: 2024-03-19T06:45:00.266Z

Link: CVE-2024-2634

cve-icon Vulnrichment

Updated: 2024-08-01T19:18:47.903Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-19T12:15:09.773

Modified: 2024-11-21T09:10:10.983

Link: CVE-2024-2634

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses