header-logo
Suggest Exploit
vendor:
CraftCms
by:
Mohammed Abdul Raheem
5.3
CVSS
MEDIUM
Sensitive information disclosure
N/A
CWE
Product Name: CraftCms
Affected Version From: CraftCms v2 before 2.7.10
Affected Version To: CraftCmsv3 before 3.2.6
Patch Exists: YES
Related CWE: CVE-2019-14280
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Windows and Linux
2019

CraftCms Users information disclosure From uploaded File

When a user uploads an image in CraftCMS, the uploaded image's EXIF Geolocation Data does not gets stripped. As a result, anyone can get sensitive information of CraftCMS's users like their Geolocation, their Device information like Device Name, Version, Software & Software version used etc.

Mitigation:

Strip EXIF Geolocation Data from uploaded images.
Source

Exploit-DB raw data: