PT-2023-5480 · Lg · Lg Simple Editor

Rgod

·

Published

2023-02-13

·

Updated

2024-09-18

·

CVE-2023-40493

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LG Simple Editor (affected versions not specified)
Description This issue allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. The specific flaw exists within the implementation of the copySessionFolder command, which lacks proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. The vulnerability can be exploited by sending a specially crafted HTTP request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the copySessionFolder command until a patch is available. Restrict access to sensitive directories to minimize the risk of exploitation. Avoid using user-supplied paths in file operations until the issue is resolved.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-06125
CVE-2023-40493
ZDI-23-1199

Affected Products

Lg Simple Editor