#VU79987 Path traversal in Simple Editor - CVE-2023-40499
Published: August 25, 2023
Simple Editor
LG Electronics
Description
The vulnerability allows a remote attacker to delete arbitrary files on the system.
The vulnerability exists due to input validation error when processing directory traversal sequences within the mkdir command implemented in the makeDetailContent method. A remote attacker can send a specially crafted HTTP request and delete arbitrary files on the system.