SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-04-14T00:00:00

Updated: 2024-08-02T14:14:40.064Z

Reserved: 2023-04-07T00:00:00

Link: CVE-2023-29850

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-14T14:15:11.733

Modified: 2023-04-25T15:49:00.603

Link: CVE-2023-29850

cve-icon Redhat

No data.