Executive brief
LG SmartShare is a software utility for Windows that allows users to share multimedia content between their PC and other smart devices like TVs. A security flaw in this software allows an attacker on the same local network to execute unauthorized database commands. This could lead to the theft of sensitive information or the manipulation of data stored within the application.
Technical details
An SQL injection vulnerability exists in LG Electronics SmartShare through version 2.3.1712.1202 due to improper neutralization of special elements used in SQL commands (CWE-89). The vulnerability is exploitable by an unauthenticated attacker located on the same local network (Adjacent vector). Successful exploitation allows the attacker to perform unauthorized queries against the underlying database, potentially leading to high confidentiality impact and low integrity impact. The software is supported on Windows 10 and earlier versions.
Affected products
- LG Electronics SmartShare through 2.3.1712.1202
Timeline
- 2026-07-30: advisory: NVD publication date