In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
| Software | From | Fixed in |
|---|---|---|
| cleo / vltrader | - | 5.8.0.21 |
| cleo / harmony | - | 5.8.0.21 |
| cleo / lexicom | - | 5.8.0.21 |