CRITICAL🇵🇱 Wersja polska

CVE-2023-40494

CVSS 9.1v3.1pub. 2024-05-03upd. 2025-04-04

LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteFolder method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. . Was ZDI-CAN-19921.

🤖 AI Analysis
How it works

The vulnerability lies in the deleteFolder method, which does not perform proper validation of the path supplied by the user before using it in file operations. An attacker can craft a request containing path traversal sequences (e.g., '../'), which allows escaping the intended application working directory. As a result, it is possible to specify and delete any file or directory accessible in the operating system. The operation is executed in the context of the SYSTEM account, which gives the attacker the highest level of access to the file system.

Impact

An attacker can delete any system or application files, which may lead to system destabilization or complete immobilization of the operating system and loss of critical data.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references. Additionally, it is recommended to restrict network access to LG Simple Editor instances using a firewall until the patch is deployed.

Who is affected

LG Simple Editor — versions indicated in the manufacturer's references and in the Zero Day Initiative guide (ZDI-23-1200)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Lg Simple Editor

    APP
    Lg
    3.21.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2023-40498CRITICAL9.8PL ✓same product

LG Simple Editor: path traversal w komendzie cp umożliwia RCE jako SYSTEM

CVE-2023-40492CRITICAL9.1PL ✓same product

LG Simple Editor — path traversal umożliwiający usunięcie dowolnych plików

CVE-2023-40493CRITICAL9.8PL ✓same product

LG Simple Editor — path traversal umożliwiający RCE jako SYSTEM

CVE-2023-40497CRITICAL9.8PL ✓same product

LG Simple Editor — path traversal umożliwiający zdalny RCE jako SYSTEM

CVE-2023-40499CRITICAL9.1PL ✓same product

LG Simple Editor – path traversal umożliwiający usunięcie dowolnych plików