CVE-2024-50623
KEV
🔴 Łataj teraz
Nieograniczony upload i download plików w Cleo Harmony, VLTrader i LexiCom umożliwia zdalne wykonanie kodu.
CVSS
9.8
EPSS
98.5%
Exploit
weaponized
Vendor
cleo
Opis źródłowy (NVD)
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 98.5% |
| Opublikowano (NVD) | 2024-10-28 00:15:03 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-31 04:16:44 UTC |
Referencje
- https://support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-Advisory (cve@mitre.org) [Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50623 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]