
CVE-2023-40510 – LG Simple Editor getServerSetting Authentication Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2023-40510
24 Aug 2023 — LG Simple Editor getServerSetting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getServerSetting method. The issue results from the exposure of plaintext credentials. • https://www.zerodayinitiative.com/advisories/ZDI-23-1214 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2023-40511 – LG Simple Editor checkServer Authentication Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2023-40511
24 Aug 2023 — LG Simple Editor checkServer Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the checkServer method. The issue results from the exposure of plaintext credentials. • https://www.zerodayinitiative.com/advisories/ZDI-23-1215 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2023-40512 – LG Simple Editor PlayerController getImageByFilename Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-40512
24 Aug 2023 — LG Simple Editor PlayerController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the getImageByFilename method in the PlayerController class. The issue results from the lack of proper validation of a user... • https://www.zerodayinitiative.com/advisories/ZDI-23-1216 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40513 – LG Simple Editor UserManageController getImageByFilename Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-40513
24 Aug 2023 — LG Simple Editor UserManageController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the getImageByFilename method in the UserManageController class. The issue results from the lack of proper validation o... • https://www.zerodayinitiative.com/advisories/ZDI-23-1195 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40514 – LG Simple Editor FileManagerController getImageByFilename Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-40514
24 Aug 2023 — LG Simple Editor FileManagerController getImageByFilename Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the getImageByFilename method in the FileManagerController class. The issue results from the lack of proper validation... • https://www.zerodayinitiative.com/advisories/ZDI-23-1196 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40515 – LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability
https://notcve.org/view.php?id=CVE-2023-40515
24 Aug 2023 — LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the joinAddUser method. The issue results from improper input validation. • https://www.zerodayinitiative.com/advisories/ZDI-23-1197 • CWE-20: Improper Input Validation •

CVE-2023-40517 – LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-40517
24 Aug 2023 — LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getObject method implemented in the ContentRestController class. The issue results from the lack of proper validation of a user-supplied path prior to using it in fi... • https://www.zerodayinitiative.com/advisories/ZDI-23-1219 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40493 – LG Simple Editor copySessionFolder Directory Traversal Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2023-40493
24 Aug 2023 — LG Simple Editor copySessionFolder Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the copySessionFolder command. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. • https://www.zerodayinitiative.com/advisories/ZDI-23-1199 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40494 – LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability
https://notcve.org/view.php?id=CVE-2023-40494
24 Aug 2023 — LG Simple Editor deleteFolder Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the deleteFolder method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. • https://www.zerodayinitiative.com/advisories/ZDI-23-1200 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-40495 – LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2023-40495
24 Aug 2023 — LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyTemplateAll method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. • https://www.zerodayinitiative.com/advisories/ZDI-23-1201 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •