Skip to content

Instantly share code, notes, and snippets.

@rxerium
Created December 10, 2024 13:09
Show Gist options
  • Select an option

  • Save rxerium/4a0bac0b57ee00821c824fd83e1f8d2d to your computer and use it in GitHub Desktop.

Select an option

Save rxerium/4a0bac0b57ee00821c824fd83e1f8d2d to your computer and use it in GitHub Desktop.
Nuclei template to detect vulnerable instances for CVE-2024-50623
id: CVE-2024-50623
info:
name: CVE-2024-50623
author: rxerium
severity: high
description: |
Unrestricted file upload and download vulnerability in Cleo Harmony, VLTrader, and LexiCom before version 5.8.0.21, leading to remote code execution
reference:
- https://support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-50623
metadata:
max-request: 1
verified: true
tags: cleo,harmony,vltrader,lexicom,rce
tcp:
- host:
- "{{Hostname}}"
matchers:
- type: word
words:
- "5.8.0.21"
negative: true
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment