CVE-2024-57727

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
Configurations

Configuration 1 (hide)

cpe:2.3:a:simple-help:simplehelp:*:*:*:*:*:*:*:*

History

16 Jan 2025, 21:22

Type Values Removed Values Added
CPE cpe:2.3:a:simple-help:simplehelp:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-22
First Time Simple-help
Simple-help simplehelp
References () https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier - () https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier - Release Notes
References () https://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/ - () https://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/ - Third Party Advisory

15 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 23:15

Updated : 2025-06-09 20:58


NVD link : CVE-2024-57727

Mitre link : CVE-2024-57727


JSON object : View

Products Affected

simple-help

  • simplehelp
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')