CVE-2024-57727: SimpleHelp Path Traversal Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2025-02-13. EPSS: 96.6% chance of exploitation in the next 30 days.

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

Affected products

  • SimpleHelp SimpleHelp: before 5.5.8 (fixed in 5.5.8)

Published 2025-01-15. Last modified 2026-08-04.