CVE-2025-23362: XSS
The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered and crafted EXIF meta data is processed, an arbitrary script may be executed on the web browser. Versions 2.3.2 and 2.4.0 were reported as vulnerable. According to the vendor, the product has been refactored after those old versions and the version 3.0.1 is not vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23362?
CVE-2025-23362 is categorized as a high severity cross-site scripting vulnerability.
How do I fix CVE-2025-23362?
To fix CVE-2025-23362, upgrade to the latest version of EXIF Viewer Classic that addresses this vulnerability.
What versions of EXIF Viewer Classic are affected by CVE-2025-23362?
CVE-2025-23362 affects EXIF Viewer Classic versions between 2.3.2 and 2.4.0.
What type of vulnerability is CVE-2025-23362?
CVE-2025-23362 is a cross-site scripting (XSS) vulnerability.
What impact does CVE-2025-23362 have on users?
CVE-2025-23362 allows attackers to execute arbitrary scripts on a user's web browser, potentially compromising sensitive information.