Description

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

INFO

Published Date :

2025-01-15T00:00:00.000Z

Last Modified :

2026-02-26T19:09:07.433Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-57727 vulnerability.

Vendors Products
Simple-help
  • Simplehelp

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact