{"id":"CVE-2024-50623","title":"In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.","summary":"In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-434","CWE-434","CWE-434"],"vendor":"cleo","product":"harmony","affected":["harmony < 5.8.0.21","lexicom < 5.8.0.21","vltrader < 5.8.0.21"],"patched":["harmony 5.8.0.21","lexicom 5.8.0.21","vltrader 5.8.0.21"],"published":"2024-10-28","updated":"2026-07-31","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-50623","references":[{"url":"https://support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-Advisory","label":"cve@mitre.org"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-50623","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.98607,"epssPercentile":0.99922,"kev":true,"kevDateAdded":"2024-12-13","kevDueDate":"2025-01-03","kevRansomware":true,"exploited":true,"ingestedAt":"2026-07-31T04:58:34.591Z","exploits":{"github":4,"githubRepos":["https://github.com/watchtowrlabs/CVE-2024-50623","https://github.com/verylazytech/CVE-2024-50623","https://github.com/iSee857/Cleo-CVE-2024-50623-PoC"],"nuclei":["CVE-2024-50623"],"checkedAt":"2026-09-20T17:26:50.029Z"},"exploitAvailable":true,"slug":"CVE-2024-50623","body":"## Overview\n\nIn Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.\n\n## Affected\n\n- `harmony < 5.8.0.21`\n- `lexicom < 5.8.0.21`\n- `vltrader < 5.8.0.21`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `harmony 5.8.0.21`\n- `lexicom 5.8.0.21`\n- `vltrader 5.8.0.21`","depth":"hadal","depthScore":100,"depthScoreParts":{"impact":53.9,"likelihood":19.7,"exploitation":25,"ransomware":5},"changes":[{"seq":4737,"id":"CVE-2024-50623","ts":1788887203087,"field":"exploit_available","old":"false","new":"true"},{"seq":3620,"id":"CVE-2024-50623","ts":1788886319246,"field":"exploit_available","old":"true","new":"false"},{"seq":2474,"id":"CVE-2024-50623","ts":1788882987795,"field":"exploit_available","old":"false","new":"true"},{"seq":1503,"id":"CVE-2024-50623","ts":1788882401350,"field":"exploit_available","old":"true","new":"false"},{"seq":617,"id":"CVE-2024-50623","ts":1788881838005,"field":"exploit_available","old":"false","new":"true"}]}