CVE-2020-26220 Information
Feb 14, 2021
cve
Description
toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation device and software version data etc (if present. The issue is fixed in version 2.0.
Reference
https://github.com/puncsky/touchbase.ai/pull/400/commits/69de77b163f6debaeb3f8d1a85367310a40d196f https://github.com/puncsky/touchbase.ai/security/advisories/GHSA-hh6j-j73p-cp3h
Share on: