First published: Fri May 03 2024(Updated: )
LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the joinAddUser method. The issue results from improper input validation. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. . Was ZDI-CAN-20048.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
LG Simple Editor |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40515 is a high severity vulnerability that can lead to a denial-of-service condition.
CVE-2023-40515 allows remote attackers to create a denial-of-service condition on affected installations.
No, authentication is not required to exploit CVE-2023-40515.
LG Simple Editor is the product affected by CVE-2023-40515.
To fix CVE-2023-40515, update LG Simple Editor to the latest version provided by the vendor.