mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
19 lines
959 B
Markdown
19 lines
959 B
Markdown
### [CVE-2024-12632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-12632)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
In Cleo Harmony up to and including 5.8.0.21, VLTrader up to and including 5.8.0.21, and LexiCom up to and including 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update
|
|
- https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|