SimpleHelp Security Update Advisory

Overview

We have released a security update to address a vulnerability in SimpleHelp. Users of affected products are advised to update to the latest version.

 

Affected Products

 

CVE-2024-57726, CVE-2024-57727, CVE-2024-57728

SimpleHelp version: ~ v5.5.7

 

 

Resolved Vulnerabilities

Vulnerability that could allow a low-privileged user to generate API keys with excessive privileges (CVE-2024-57726)
Path traversal vulnerability that could allow arbitrary file downloads (CVE-2024-57727)
Vulnerability that could allow arbitrary file upload by uploading a special ZIP file (CVE-2024-57728)

 

 

Vulnerability Patches

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-57726, CVE-2024-57727, CVE-2024-57728

SimpleHelp versions: v5.5.8, v5.4.10, v5.3.9

 

References

[1] Security Vulnerabilities in SimpleHelp 5.5.7 and earlier
https://simple-help.com/kb—security-vulnerabilities-01-2025#vulnerability-details