CyberICT

CVE-2024-50623

Cleo · Published October 28, 2024

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

Affected Products

  • Harmony < 5.8.0.21
  • Lexicom < 5.8.0.21
  • Vltrader < 5.8.0.21

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H