CVE-2024-57728
Description
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
Summary dbcve.org
SimpleHelp remote support software versions 5.5.7 and prior contain a zip slip vulnerability allowing authenticated admin users to craft malicious zip archives that, when uploaded, extract files to arbitrary filesystem paths via directory traversal sequences. This enables remote code execution in the context of the SimpleHelp server user.
Mitigation
Apply vendor patch/update to SimpleHelp v5.5.8 or later. Until patched, restrict admin user privileges to trusted personnel only and monitor file upload operations for traversal patterns.