Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-0724: Insecure Storage of Sensitive Information in microweber

Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

CVE
#vulnerability#web#google#git

Description:-

When the user uploads his profile picture, the uploaded image’s EXIF Geolocation Data does not get stripped. As a result, anyone can get sensitive information of microweber users like their Geolocation, their Device information like Device Name, Version, Software & Software version used, etc.

Proof of Concept:-

1.Browse this link:- https://github.com/ianare/exif-samples/blob/master/jpg/gps/DSCN0012.jpg

2.Download the image Upload the picture on your profile and click on save.

3.Now see the path of the uploaded image ( Either by right click on image then copy image address OR right-click, inspect the image, the URL will come in the inspect, edit it as HTML )

4.Then open:- http://exif.regex.info/exif.cgi

5.Paste the URL (https://demo.microweber.org/demo/userfiles/media/default/dscn0012.jpg) of the profile image path now you can see the EXIF data.

Image PoC:-

https://drive.google.com/file/d/154yIOLwwVKmG7RWdqD25rwpaOUZH-X1X/view?usp=sharing

Impact:-

This vulnerability impacts all users on microweber. This vulnerability violates the privacy of a User and shares sensitive information of the user who uploads their profile picture on microweber.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907