HIGH

CVE-2024-57728

Simple-help Simplehelp 2025-01-15 CVSS v3.1
CVSS
7.2
KEV

Description

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

Summary dbcve.org

SimpleHelp remote support software versions 5.5.7 and prior contain a zip slip vulnerability allowing authenticated admin users to craft malicious zip archives that, when uploaded, extract files to arbitrary filesystem paths via directory traversal sequences. This enables remote code execution in the context of the SimpleHelp server user.

Mitigation

Apply vendor patch/update to SimpleHelp v5.5.8 or later. Until patched, restrict admin user privileges to trusted personnel only and monitor file upload operations for traversal patterns.

Weakness (CWE)

CWE-59 Link Following (Symlink)
CWE-22 Path Traversal

EPSS Score

6.98%
Probability of exploitation in next 30 days
93.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE