CVE-2019-14280: Infoleak
Published Jul 26, 2019
·Updated
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Affected Software
2 affected components
Craft CMS>=2.0.2524<2.7.10
Craft CMS>=3.0.0<3.2.6
Event History
Jul 26, 2019
CVE Published
via MITRE·03:52 AM
Data Sourced
via MITRE·03:52 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Craft CMS vulnerability?
The vulnerability ID for this Craft CMS vulnerability is CVE-2019-14280.
2
What is the severity of CVE-2019-14280?
The severity of CVE-2019-14280 is medium with a CVSS score of 5.3.
3
What is the affected software version for CVE-2019-14280?
Craft CMS versions before 2.7.10 and 3 before 3.2.6 are affected by CVE-2019-14280.
4
What is the impact of CVE-2019-14280?
CVE-2019-14280 could potentially expose personal/geolocation data to the public.
5
How can I fix CVE-2019-14280?
To fix CVE-2019-14280, you should update Craft CMS to version 2.7.10 for Craft 2 or version 3.2.6 for Craft 3.