Описание
Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise latitude and longitude coordinates revealing user physical location at capture time.
EPSS
Процентиль: 27%
0.00343
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 5.3
github
3 месяца назад
Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise latitude and longitude coordinates revealing user physical location at capture time.
EPSS
Процентиль: 27%
0.00343
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-200