CVE-2023-40515

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
03/05/2024
Last modified:
10/04/2025

Description

LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability.<br /> <br /> The specific flaw exists within the joinAddUser method. The issue results from improper input validation. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.<br /> . Was ZDI-CAN-20048.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lg:simple_editor:3.21.0:*:*:*:*:*:*:*