LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteCheckSession method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. . Was ZDI-CAN-19919.
The vulnerability occurs in the deleteCheckSession method, which does not properly validate the path supplied by the user before using it in file operations. An attacker can submit a crafted path containing path traversal sequences (e.g., '../'), thereby bypassing the intended application working directory. As a result, it is possible to target and delete arbitrary files on the server, and the operation is executed with SYSTEM account privileges.
An attacker can permanently delete arbitrary files on the compromised system with SYSTEM privileges, which may lead to disruption of the operating system, applications, or data loss. It is also possible to deliberately delete critical system files resulting in service unavailability.
Apply patches available from the vendor according to the references (https://www.zerodayinitiative.com/advisories/ZDI-23-1198/). Until the update is applied, it is recommended to restrict network access to the LG Simple Editor application exclusively to trusted hosts using a firewall or network segmentation.
LG Simple Editor — versions indicated in the vendor's references (ZDI-CAN-19919 report)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HLg Simple Editor
APPLg3.21.0
Related vulnerabilities
LG Simple Editor: path traversal w komendzie cp umożliwia RCE jako SYSTEM
LG Simple Editor — path traversal umożliwiający RCE jako SYSTEM
LG Simple Editor — path traversal umożliwiający usunięcie dowolnych plików
LG Simple Editor — path traversal umożliwiający zdalny RCE jako SYSTEM
LG Simple Editor – path traversal umożliwiający usunięcie dowolnych plików