Exploit for #VU101392 Arbitrary file upload in Cleo products


| Updated: 2025-01-03

Vulnerability identifier: #VU101392

Vulnerability risk: High

CVSSv4.0: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber]

CVE-ID: CVE-2024-50623

CWE-ID: CWE-434

Exploitation vector: Network

Exploits in database: 3

Vulnerable software:
Cleo Harmony
Web applications / Remote management & hosting panels
Cleo VLTrader
Web applications / Remote management & hosting panels
Cleo LexiCom
Web applications / Remote management & hosting panels

Vendor: Cleo