Vulnerability Description
toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software version data etc (if present. The issue is fixed in version 2.0.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Touchbase.Ai Project | Touchbase.Ai | < 2.0 |
Related Weaknesses (CWE)
References
- https://github.com/puncsky/touchbase.ai/pull/400/commits/69de77b163f6debaeb3f8d1PatchThird Party Advisory
- https://github.com/puncsky/touchbase.ai/security/advisories/GHSA-hh6j-j73p-cp3hThird Party Advisory
- https://github.com/puncsky/touchbase.ai/pull/400/commits/69de77b163f6debaeb3f8d1PatchThird Party Advisory
- https://github.com/puncsky/touchbase.ai/security/advisories/GHSA-hh6j-j73p-cp3hThird Party Advisory
FAQ
What is CVE-2020-26220?
CVE-2020-26220 is a vulnerability with a CVSS score of 3.5 (LOW). toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software vers...
How severe is CVE-2020-26220?
CVE-2020-26220 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26220?
Check the references section above for vendor advisories and patch information. Affected products include: Touchbase.Ai Project Touchbase.Ai.