This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/thumbnail endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of the current user.
Use CWE-22, Lg vendor hub and Lg Led Assistant product page to widen CVE-2023-4616 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-4614, CVE-2023-4613 and CVE-2024-2862 for nearby disclosures in the same product family.