Description
A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sse_generico/generico_login.jsp' is vulnerable to XSS attack via 'lang' query, i.e. '/sse_generico/generico_login.jsp?lang=%27%3balert(%27BLEUSS%27)%2f%2f¶ms='.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Any product with all fixes applied after 2013 is not vulnerable to this XSS.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27583 | A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint '/sse_generico/generico_login.jsp' is vulnerable to XSS attack via 'lang' query, i.e. '/sse_generico/generico_login.jsp?lang=%27%3balert(%27BLEUSS%27)%2f%2f¶ms='. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T19:18:47.903Z
Reserved: 2024-03-19T06:45:00.266Z
Link: CVE-2024-2634
Updated: 2024-08-01T19:18:47.903Z
Status : Deferred
Published: 2024-03-19T12:15:09.773
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-2634
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD