CVE-2023-29850

SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.
References
Link Resource
https://github.com/slims/slims9_bulian/issues/186 Exploit Issue Tracking Vendor Advisory
https://github.com/slims/slims9_bulian/issues/186 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:slims:senayan_library_management_system:9.5.2:*:*:*:*:*:*:*

History

06 Feb 2025, 21:15

Type Values Removed Values Added
CWE CWE-203

Information

Published : 2023-04-14 14:15

Updated : 2025-02-06 21:15


NVD link : CVE-2023-29850

Mitre link : CVE-2023-29850

CVE.ORG link : CVE-2023-29850


JSON object : View

Products Affected

slims

  • senayan_library_management_system
CWE
NVD-CWE-noinfo CWE-203

Observable Discrepancy