Loading HuntDB...

GHSA-j8cx-j9j2-f29w

GitHub Security Advisory

Insecure Storage of Sensitive Information in Microweber

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Microweber prior to version 1.3 does not strip images of EXIF data, exposing information about users' locations, device hardware, and device software.

Affected Packages

Packagist microweber/microweber
Affected versions: 0 (fixed in 1.3)

Related CVEs

Key Information

GHSA ID
GHSA-j8cx-j9j2-f29w
Published
February 24, 2022 12:00 AM
Last Modified
February 24, 2022 10:27 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
microweber/microweber
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 3, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.