ZDI-CAN-20270: ZDI-23-1224: LG LED Assistant updateFile Directory Traversal Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this LG LED Assistant vulnerability?
The vulnerability ID of this LG LED Assistant vulnerability is ZDI-CAN-20270.
What is the severity of the LG LED Assistant vulnerability ZDI-CAN-20270?
The severity of the LG LED Assistant vulnerability ZDI-CAN-20270 is high with a severity value of 7.5.
What is the affected software by the LG LED Assistant vulnerability ZDI-CAN-20270?
The affected software by the LG LED Assistant vulnerability ZDI-CAN-20270 is LG LED Assistant.
What is the authentication requirement to exploit the LG LED Assistant vulnerability ZDI-CAN-20270?
Authentication is not required to exploit the LG LED Assistant vulnerability ZDI-CAN-20270.
What is the specific flaw within the LG LED Assistant vulnerability ZDI-CAN-20270?
The specific flaw within the LG LED Assistant vulnerability ZDI-CAN-20270 is the lack of proper validation in the /api/download/updateFile endpoint, allowing for directory traversal and information disclosure.