SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.
References
| Link | Resource |
|---|---|
| https://github.com/slims/slims9_bulian/issues/186 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/slims/slims9_bulian/issues/186 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
06 Feb 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-203 |
Information
Published : 2023-04-14 14:15
Updated : 2025-02-06 21:15
NVD link : CVE-2023-29850
Mitre link : CVE-2023-29850
CVE.ORG link : CVE-2023-29850
JSON object : View
Products Affected
slims
- senayan_library_management_system
CWE
