← Back

CVE-2024-57727

Published: Jan 15, 2025Modified: Nov 4, 2025CISA KEV

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

Affected (1)

1 product
Simplehelp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.5.8

Timeline

No history available yet.