CVE-2024-57727

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
15/01/2025
Last modified:
09/06/2025

Description

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:simple-help:simplehelp:*:*:*:*:*:*:*:* 5.5.8 (excluding)