A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sse_generico/generico_login.jsp' is vulnerable to XSS attack via 'lang' query, i.e. '/sse_generico/generico_login.jsp?lang=%27%3balert(%27BLEUSS%27)%2f%2f¶ms='.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27583 | A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sse_generico/generico_login.jsp' is vulnerable to XSS attack via 'lang' query, i.e. '/sse_generico/generico_login.jsp?lang=%27%3balert(%27BLEUSS%27)%2f%2f¶ms='. |
Fixes
Solution
Any product with all fixes applied after 2013 is not vulnerable to this XSS.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T19:18:47.903Z
Reserved: 2024-03-19T06:45:00.266Z
Link: CVE-2024-2634
Updated: 2024-08-01T19:18:47.903Z
Status : Awaiting Analysis
Published: 2024-03-19T12:15:09.773
Modified: 2024-11-21T09:10:10.983
Link: CVE-2024-2634
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD