Skip to content

Instantly share code, notes, and snippets.

@emadshanab
Forked from rxerium/CVE-2024-50623.yaml
Created October 12, 2025 00:42
Show Gist options
  • Select an option

  • Save emadshanab/5067c5055f2656e694af9c7a26104a71 to your computer and use it in GitHub Desktop.

Select an option

Save emadshanab/5067c5055f2656e694af9c7a26104a71 to your computer and use it in GitHub Desktop.
Nuclei template to detect vulnerable instances for CVE-2024-50623
id: CVE-2024-50623
info:
name: CVE-2024-50623
author: rxerium
severity: high
description: |
Unrestricted file upload and download vulnerability in Cleo Harmony, VLTrader, and LexiCom before version 5.8.0.21, leading to remote code execution
reference:
- https://support.cleo.com/hc/en-us/articles/27140294267799-Cleo-Product-Security-Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-50623
metadata:
max-request: 1
verified: true
tags: cleo,harmony,vltrader,lexicom,rce
tcp:
- host:
- "{{Hostname}}"
matchers:
- type: word
words:
- "5.8.0.21"
negative: true
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment