ZDI-23-1198: (0Day) LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability
Published Aug 24, 2023
·Updated
This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
LG Simple Editor
Event History
Aug 24, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:23 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-1198?
The severity of ZDI-23-1198 is critical due to its ability to allow remote attackers to delete arbitrary files.
2
How do I fix ZDI-23-1198?
To mitigate ZDI-23-1198, you should apply any available security updates from LG for Simple Editor.
3
What impact does ZDI-23-1198 have on LG Simple Editor?
ZDI-23-1198 allows unauthorized remote deletion of files, potentially leading to data loss or system compromise.
4
Can ZDI-23-1198 be exploited without authentication?
Yes, ZDI-23-1198 can be exploited by remote attackers without the need for authentication.
5
Which versions of LG Simple Editor are affected by ZDI-23-1198?
ZDI-23-1198 affects all vulnerable installations of LG Simple Editor, though specific version details may vary.