CVE-2023-29850

SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information.
References
Link Resource
https://github.com/slims/slims9_bulian/issues/186 Exploit Issue Tracking Vendor Advisory
https://github.com/slims/slims9_bulian/issues/186 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:slims:senayan_library_management_system:9.5.2:*:*:*:*:*:*:*

History

06 Feb 2025, 21:15

Type Values Removed Values Added
CWE CWE-203

21 Nov 2024, 07:57

Type Values Removed Values Added
References () https://github.com/slims/slims9_bulian/issues/186 - Exploit, Issue Tracking, Vendor Advisory () https://github.com/slims/slims9_bulian/issues/186 - Exploit, Issue Tracking, Vendor Advisory

25 Apr 2023, 15:49

Type Values Removed Values Added
References (MISC) https://github.com/slims/slims9_bulian/issues/186 - (MISC) https://github.com/slims/slims9_bulian/issues/186 - Exploit, Issue Tracking, Vendor Advisory
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:slims:senayan_library_management_system:9.5.2:*:*:*:*:*:*:*

14 Apr 2023, 22:45

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-14 14:15

Updated : 2025-02-06 21:15


NVD link : CVE-2023-29850

Mitre link : CVE-2023-29850

CVE.ORG link : CVE-2023-29850


JSON object : View

Products Affected

slims

  • senayan_library_management_system
CWE
NVD-CWE-noinfo CWE-203

Observable Discrepancy