CVE-2024-57727
Description
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
Summary dbcve.org
SimpleHelp remote support software versions 5.5.7 and earlier contain multiple path traversal vulnerabilities that allow unauthenticated remote attackers to craft HTTP requests with directory traversal sequences (e.g., ../../../') to escape the web root and download arbitrary files from the server filesystem. The vulnerability is particularly critical because it exposes sensitive configuration files containing server secrets and hashed user passwords.
Mitigation
Upgrade SimpleHelp to a version newer than 5.5.7, or apply vendor-supplied patches. If immediate patching is not feasible, implement network-level access controls to restrict exposure of the SimpleHelp server to untrusted networks.