CRITICAL🇵🇱 Wersja polska

CVE-2023-40492

CVSS 9.1v3.1pub. 2024-05-03upd. 2025-04-23

LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteCheckSession method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. . Was ZDI-CAN-19919.

🤖 AI Analysis
How it works

The vulnerability occurs in the deleteCheckSession method, which does not properly validate the path supplied by the user before using it in file operations. An attacker can submit a crafted path containing path traversal sequences (e.g., '../'), thereby bypassing the intended application working directory. As a result, it is possible to target and delete arbitrary files on the server, and the operation is executed with SYSTEM account privileges.

Impact

An attacker can permanently delete arbitrary files on the compromised system with SYSTEM privileges, which may lead to disruption of the operating system, applications, or data loss. It is also possible to deliberately delete critical system files resulting in service unavailability.

Mitigation & patch

Apply patches available from the vendor according to the references (https://www.zerodayinitiative.com/advisories/ZDI-23-1198/). Until the update is applied, it is recommended to restrict network access to the LG Simple Editor application exclusively to trusted hosts using a firewall or network segmentation.

Who is affected

LG Simple Editor — versions indicated in the vendor's references (ZDI-CAN-19919 report)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Lg Simple Editor

    APP
    Lg
    3.21.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2023-40498CRITICAL9.8PL ✓same product

LG Simple Editor: path traversal w komendzie cp umożliwia RCE jako SYSTEM

CVE-2023-40493CRITICAL9.8PL ✓same product

LG Simple Editor — path traversal umożliwiający RCE jako SYSTEM

CVE-2023-40494CRITICAL9.1PL ✓same product

LG Simple Editor — path traversal umożliwiający usunięcie dowolnych plików

CVE-2023-40497CRITICAL9.8PL ✓same product

LG Simple Editor — path traversal umożliwiający zdalny RCE jako SYSTEM

CVE-2023-40499CRITICAL9.1PL ✓same product

LG Simple Editor – path traversal umożliwiający usunięcie dowolnych plików