
CVE-2023-40513 – LG Simple Editor UserManageController getImageByFilename Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-40513
24 Aug 2023 — LG Simple Editor UserManageController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the getImageByFilename method in the UserManageController class. The issue results from the lack of proper validation o... • https://www.zerodayinitiative.com/advisories/ZDI-23-1195 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40514 – LG Simple Editor FileManagerController getImageByFilename Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-40514
24 Aug 2023 — LG Simple Editor FileManagerController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the getImageByFilename method in the FileManagerController class. The issue results from the lack of proper validation... • https://www.zerodayinitiative.com/advisories/ZDI-23-1196 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40515 – LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability
https://notcve.org/view.php?id=CVE-2023-40515
24 Aug 2023 — LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the joinAddUser method. The issue results from improper input validation. • https://www.zerodayinitiative.com/advisories/ZDI-23-1197 • CWE-20: Improper Input Validation •

CVE-2023-40516 – LG Simple Editor Incorrect Permission Assignment Local Privilege Escalation Vulnerability
https://notcve.org/view.php?id=CVE-2023-40516
24 Aug 2023 — LG Simple Editor Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of LG Simple Editor. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product installer. The product sets incorrect permissions on folders. • https://www.zerodayinitiative.com/advisories/ZDI-23-1218 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2023-40493 – LG Simple Editor copySessionFolder Directory Traversal Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-40493
24 Aug 2023 — LG Simple Editor copySessionFolder Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the copySessionFolder command. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. • https://www.zerodayinitiative.com/advisories/ZDI-23-1199 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40494 – LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability
https://notcve.org/view.php?id=CVE-2023-40494
24 Aug 2023 — LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteFolder method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. • https://www.zerodayinitiative.com/advisories/ZDI-23-1200 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-41181 – LG SuperSign Media Editor getSubFolderList Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-41181
24 Aug 2023 — LG SuperSign Media Editor getSubFolderList Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getSubFolderList method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. • https://www.zerodayinitiative.com/advisories/ZDI-23-1220 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40492 – LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability
https://notcve.org/view.php?id=CVE-2023-40492
24 Aug 2023 — LG Simple Editor deleteCheckSession Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteCheckSession method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. • https://www.zerodayinitiative.com/advisories/ZDI-23-1198 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40495 – LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-40495
24 Aug 2023 — LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyTemplateAll method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. • https://www.zerodayinitiative.com/advisories/ZDI-23-1201 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40517 – LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-40517
24 Aug 2023 — LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getObject method implemented in the ContentRestController class. The issue results from the lack of proper validation of a user-supplied path prior to using it in fi... • https://www.zerodayinitiative.com/advisories/ZDI-23-1219 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •