SimpleHelp Security Update Advisory
Overview
We have released a security update to address a vulnerability in SimpleHelp. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2024-57726, CVE-2024-57727, CVE-2024-57728
SimpleHelp version: ~ v5.5.7
Resolved Vulnerabilities
Vulnerability that could allow a low-privileged user to generate API keys with excessive privileges (CVE-2024-57726)
Path traversal vulnerability that could allow arbitrary file downloads (CVE-2024-57727)
Vulnerability that could allow arbitrary file upload by uploading a special ZIP file (CVE-2024-57728)
Vulnerability Patches
Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-57726, CVE-2024-57727, CVE-2024-57728
SimpleHelp versions: v5.5.8, v5.4.10, v5.3.9
References
[1] Security Vulnerabilities in SimpleHelp 5.5.7 and earlier
https://simple-help.com/kb—security-vulnerabilities-01-2025#vulnerability-details