A path traversal vulnerability exists in the endpoint handler for /api/thumbnail in Common.js. An unauthenticated remote attacker can exploit this to upload arbitrary files to any location on the disk drive where the product is installed.
id: CVE-2024-2863
info:
name: LG LED Assistant - Thumbnail Path Traversal File Upload
author: b
...