THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-50623 (CRITICAL 9.8) — In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

[NVD] CVE-2024-50623 (CRITICAL 9.8) — In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

lownvdPublished 2024-10-28

CVE-2024-50623 CVSS: 9.8 CRITICAL Published: 2024-10-28T00:15:03.657

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-50623