CISA Known Exploited Vulnerability (KEV)
Cleo Multiple Products Unrestricted File Upload Vulnerability
December 13, 2024
January 3, 2025
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-434 |
Unrestricted Upload of File with Dangerous Type |