toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software version data etc (if present. The issue is fixed in version 2.0.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2020-11-11T22:15:14

Updated: 2020-11-11T22:15:14

Reserved: 2020-10-01T00:00:00


Link: CVE-2020-26220

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-11-11T23:15:11.477

Modified: 2020-11-17T17:21:02.567


Link: CVE-2020-26220

JSON object: View

cve-icon Redhat Information

No data.

CWE