CVE-2024-55956CISA KEV: Actively Exploited

Cleo Multiple Products Unauthenticated File Upload Vulnerability

Published Dec 17, 2024·Updated Dec 17, 2024

Description

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free