CVE-2024-50623: Cleo Multiple Products Unrestricted File Upload Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-12-13. EPSS: 98.6% chance of exploitation in the next 30 days.
In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
Affected products
- Cleo Harmony: before 5.8.0.21 (fixed in 5.8.0.21)
- Cleo Lexicom: before 5.8.0.21 (fixed in 5.8.0.21)
- Cleo Vltrader: before 5.8.0.21 (fixed in 5.8.0.21)
Published 2024-10-28. Last modified 2026-10-08.