SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/slims/slims9_bulian/issues/186 |
|
History
Thu, 06 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-203 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-14T00:00:00.000Z
Updated: 2025-02-06T20:37:56.085Z
Reserved: 2023-04-07T00:00:00.000Z
Link: CVE-2023-29850
Updated: 2024-08-02T14:14:40.064Z
Status : Modified
Published: 2023-04-14T14:15:11.733
Modified: 2025-02-06T21:15:20.580
Link: CVE-2023-29850
No data.