Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-14280

In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.159
EPSS Ranking 94.4%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2019-14280


Contact Us

Shodan ® - All rights reserved