CVE-2019-14280
26.07.2019, 04:15
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.Enginsight
Vendor | Product | Version |
---|---|---|
craftcms | craft_cms | 2.0.2524 ≤ 𝑥 < 2.7.10 |
craftcms | craft_cms | 3.0.0 ≤ 𝑥 < 3.2.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References