CVE-2022-0724
EPSS 0.46%Insecure Storage of Sensitive Information in Microweber
Published: 2/24/2022Modified: 12/5/2024
Also known as:GHSA-j8cx-j9j2-f29w
Description
Microweber prior to version 1.3 does not strip images of EXIF data, exposing information about users' locations, device hardware, and device software.
Affected packages (1)
- Packagist/microweber/microweberfrom 0, < 1.3