HTTP: LG Simple Editor copyStickerContent Directory Traversal

This signature detects attempts to exploit a known vulnerability against LG Simple Editor. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

LG Simple Editor copyStickerContent Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the copyStickerContent command. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. . Was ZDI-CAN-19923.

Affected Products

Lg simple_editor

Short Name
HTTP:DIR:LG-SE-CPY-STKR-DIR-TRV
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2023-40495 CVE-2023-40496 CVE-2023-40497 Directory Editor LG Simple Traversal copyStickerContent
Release Date
09/29/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3799
False Positive
Rarely
Vendors

Lg

Found a potential security threat?