Vulnerability Description
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Craftcms | Craft Cms | >= 2.0.2524, < 2.7.10 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/154276/Craft-CMS-2.7.9-3.2.5-Information-Di
- https://github.com/craftcms/cms/blob/develop-v2/CHANGELOG-v2.md#2710---2019-07-2Release NotesThird Party Advisory
- https://github.com/craftcms/cms/blob/develop/CHANGELOG-v3.md#326---2019-07-23Release NotesThird Party Advisory
- http://packetstormsecurity.com/files/154276/Craft-CMS-2.7.9-3.2.5-Information-Di
- https://github.com/craftcms/cms/blob/develop-v2/CHANGELOG-v2.md#2710---2019-07-2Release NotesThird Party Advisory
- https://github.com/craftcms/cms/blob/develop/CHANGELOG-v3.md#326---2019-07-23Release NotesThird Party Advisory
FAQ
What is CVE-2019-14280?
CVE-2019-14280 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to ...
How severe is CVE-2019-14280?
CVE-2019-14280 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14280?
Check the references section above for vendor advisories and patch information. Affected products include: Craftcms Craft Cms.