Vulnerability record · CVE-2023-40497 · published 3 May 2024
CVE-2023-40497: LG Simple Editor saveXml path traversal leads to remote code execution
Lg · Simple Editor
LG Simple Editor fails to validate a user-supplied path in the saveXml command implemented in the makeDetailContent method, allowing directory traversal. Because the flaw is reachable without authentication and leads to code execution as SYSTEM, it is a serious pre-auth remote code execution issue for any exposed installation.
Description
LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the saveXml command implemented in the makeDetailContent method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. . Was ZDI-CAN-19924.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable code execution as SYSTEM with a 9.8 CVSS score and very high EPSS probability makes this an urgent patching priority.
What it is
LG Simple Editor fails to validate a user-supplied path in the saveXml command implemented in the makeDetailContent method, allowing directory traversal. Because the flaw is reachable without authentication and leads to code execution as SYSTEM, it is a serious pre-auth remote code execution issue for any exposed installation.
Impact
An unauthenticated remote attacker can write files outside the intended directory and execute arbitrary code with SYSTEM privileges on the affected host.
Attack surface
Reachable over the network via the saveXml command path in makeDetailContent; the CVSS vector shows no privileges required and no user interaction, so no authentication is needed.
Exploitation
Not listed in CISA KEV and no public exploit references are given beyond the ZDI advisory, but EPSS is very high (0.69355, 99.3rd percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the vendor fix for LG Simple Editor as soon as an update is available; treat this as the primary action.
- Remove or restrict network access to LG Simple Editor instances, especially from untrusted networks or the internet.
- Run the application with least privilege rather than SYSTEM where feasible to limit post-exploitation impact.
- Monitor and restrict file write paths used by the saveXml/makeDetailContent functionality to prevent traversal outside intended directories.
Detection
- Monitor for file creation or modification outside expected Simple Editor content directories, particularly paths containing traversal sequences.
- Alert on unexpected child processes or command execution spawned by the Simple Editor service account.
- Review network logs for external connections to Simple Editor management or service ports from untrusted sources.
- Audit application logs for saveXml or makeDetailContent requests with suspicious path parameters.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-23-1203/ | Third Party Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-23-1203/ | Third Party Advisory |
Track CVE-2023-40497 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-40497), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.