📦 Simple Editor

by Lg

🔍 What is Simple Editor?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-40504

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on LG Simple Editor installations without authentication. Attackers can inject malicious commands through the readVideoInfo method,...

CVE-2023-40508

CRITICAL CVSS 9.1 May 3, 2024

This vulnerability in LG Simple Editor allows remote attackers without authentication to delete arbitrary files on affected systems by exploiting a directory traversal flaw in the putCanvasDB method. ...

CVE-2023-40499

CRITICAL CVSS 9.1 May 3, 2024

This vulnerability in LG Simple Editor allows remote attackers to delete arbitrary files without authentication by exploiting a directory traversal flaw in the mkdir command. Attackers can delete syst...

CVE-2023-40501

CRITICAL CVSS 9.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code as SYSTEM on affected LG Simple Editor installations without authentication. Attackers can exploit an exposed dangerous function in...

CVE-2023-40494

CRITICAL CVSS 9.1 May 3, 2024

This vulnerability in LG Simple Editor allows remote attackers to delete arbitrary files without authentication by exploiting a directory traversal flaw in the deleteFolder method. Attackers can delet...

CVE-2023-40497

CRITICAL CVSS 9.8 May 3, 2024

This is a critical directory traversal vulnerability in LG Simple Editor that allows unauthenticated remote attackers to write arbitrary files and execute code with SYSTEM privileges. It affects all i...

CVE-2023-40492

CRITICAL CVSS 9.1 May 3, 2024

This vulnerability allows unauthenticated remote attackers to delete arbitrary files on systems running vulnerable versions of LG Simple Editor. Attackers can exploit a directory traversal flaw in the...

CVE-2023-40515

HIGH CVSS 7.5 May 3, 2024

This vulnerability allows remote attackers to cause a denial-of-service condition on LG Simple Editor installations without requiring authentication. The flaw exists in the joinAddUser method due to i...

CVE-2023-40510

HIGH CVSS 7.5 May 3, 2024

This vulnerability allows remote attackers to bypass authentication on LG Simple Editor installations by exploiting a flaw in the getServerSetting method that exposes plaintext credentials. Any organi...

CVE-2023-40506

HIGH CVSS 7.5 May 3, 2024

This XXE vulnerability in LG Simple Editor allows remote attackers to read arbitrary files from the system without authentication. Attackers can exploit the copyContent command's improper XML parsing ...

CVE-2023-40503

HIGH CVSS 7.5 May 3, 2024

This vulnerability in LG Simple Editor allows remote attackers to read sensitive files from the system without authentication by exploiting an XML External Entity (XXE) flaw. Attackers can craft malic...

CVE-2023-40496

HIGH CVSS 7.5 May 3, 2024

This vulnerability in LG Simple Editor allows remote attackers to read sensitive files on the system without authentication. Attackers can exploit a directory traversal flaw in the copyStickerContent ...

CVE-2023-40512

MEDIUM CVSS 6.5 May 3, 2024

This vulnerability in LG Simple Editor allows authenticated attackers to bypass authentication and perform directory traversal attacks via the getImageByFilename method. Attackers can read arbitrary f...

CVE-2023-40514

MEDIUM CVSS 6.5 May 3, 2024

This vulnerability in LG Simple Editor allows authenticated attackers to bypass authentication and perform directory traversal attacks via the getImageByFilename method. Attackers can read arbitrary f...