CVE-2024-2636: Cegid META4 Hr

Critical severity, CVSS 9.0. EPSS: 0.6% chance of exploitation in the next 30 days.

An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/config/espanol/update_password.jsp' file. Modifying the 'M4_NEW_PASSWORD' parameter, an attacker could store a malicious JSP file inside the file directory, to be executed the the file is loaded in the application.

Affected products

  • Cegid META4 Hr: version 819.001.022 only

Published 2024-03-19. Last modified 2026-06-17.