← Back to browse · API

CVE-2024-57728

Severity
HIGH
CVSS
7.2
EPSS
0.06982
Risk score
56.24
CISA KEV
Yes
PoC
No
Published
2026-04-24
Modified
2026-04-24
First seen
2026-08-07
Aliases
EUVD-2024-53726, GHSA-MCHM-7MQX-7299
Products
SimpleHelp:SimpleHelp, n/a:n/a n/a
Sources
euvd EUVD-2024-53726
cisa.gov CVE-2024-57728

Description

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

References