First published: Fri Aug 25 2023(Updated: )
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability.
Affected Software | Affected Version | How to fix |
---|---|---|
LG LED Assistant |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this LG LED Assistant vulnerability is ZDI-CAN-20270.
The severity of the LG LED Assistant vulnerability ZDI-CAN-20270 is high with a severity value of 7.5.
The affected software by the LG LED Assistant vulnerability ZDI-CAN-20270 is LG LED Assistant.
Authentication is not required to exploit the LG LED Assistant vulnerability ZDI-CAN-20270.
The specific flaw within the LG LED Assistant vulnerability ZDI-CAN-20270 is the lack of proper validation in the /api/download/updateFile endpoint, allowing for directory traversal and information disclosure.