LG Simple Editor mkdir Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mkdir command implemented in the makeDetailContent method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. . Was ZDI-CAN-19926.
The vulnerability lies in the implementation of the mkdir command within the makeDetailContent method. The application does not perform proper validation of the user-supplied path before using it in file operations. An attacker can craft a request containing path traversal sequences (e.g., '../') that allow escaping the intended working directory and pointing to any location in the file system. In this way, it is possible to delete selected files with SYSTEM account privileges.
An attacker can permanently delete arbitrary files on the compromised system with SYSTEM privileges, which may lead to data integrity violation, system destabilization, or complete operating system shutdown.
Patches available from the manufacturer should be applied in accordance with the references. Details regarding the version containing the fix can be found in the Zero Day Initiative advisory at: https://www.zerodayinitiative.com/advisories/ZDI-23-1205/
LG Simple Editor – versions indicated in manufacturer references and in the Zero Day Initiative advisory (ZDI-CAN-19926)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HLg Simple Editor
APPLg3.21.0
Related vulnerabilities
LG Simple Editor — path traversal umożliwiający zdalny RCE jako SYSTEM
LG Simple Editor — path traversal umożliwiający usunięcie dowolnych plików
LG Simple Editor — path traversal umożliwiający RCE jako SYSTEM
LG Simple Editor — path traversal umożliwiający usunięcie dowolnych plików
LG Simple Editor: path traversal w komendzie cp umożliwia RCE jako SYSTEM