vendor:
CraftCms
by:
Mohammed Abdul Raheem
5.3
CVSS
MEDIUM
Sensitive information disclosure
N/A
CWE
Product Name: CraftCms
Affected Version From: CraftCms v2 before 2.7.10
Affected Version To: CraftCmsv3 before 3.2.6
Patch Exists: YES
Related CWE: CVE-2019-14280
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows and Linux
2019
CraftCms Users information disclosure From uploaded File
When a user uploads an image in CraftCMS, the uploaded image's EXIF Geolocation Data does not gets stripped. As a result, anyone can get sensitive information of CraftCMS's users like their Geolocation, their Device information like Device Name, Version, Software & Software version used etc.
Mitigation:
Strip EXIF Geolocation Data from uploaded images.