mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
27 lines
1.1 KiB
Markdown
27 lines
1.1 KiB
Markdown
|
|
### [CVE-2024-50623](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50623)
|
||
|
|

|
||
|
|

|
||
|
|

|
||
|
|
|
||
|
|
### Description
|
||
|
|
|
||
|
|
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
|
||
|
|
|
||
|
|
### POC
|
||
|
|
|
||
|
|
#### Reference
|
||
|
|
- https://support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-Advisory
|
||
|
|
|
||
|
|
#### Github
|
||
|
|
- https://github.com/Ostorlab/KEV
|
||
|
|
- https://github.com/congdong007/CVE-2024-50623-poc
|
||
|
|
- https://github.com/fl4m3-s/Cleo_Unauth_RCE
|
||
|
|
- https://github.com/iSee857/Cleo-CVE-2024-50623-PoC
|
||
|
|
- https://github.com/packetinside/CISA_BOT
|
||
|
|
- https://github.com/plzheheplztrying/cve_monitor
|
||
|
|
- https://github.com/schmalle/vltrader-vulnerability-analysis
|
||
|
|
- https://github.com/tylzars/awesome-vrre-writeups
|
||
|
|
- https://github.com/verylazytech/CVE-2024-50623
|
||
|
|
- https://github.com/watchtowrlabs/CVE-2024-50623
|
||
|
|
|