CVE-2019-14280 describes an information disclosure vulnerability in Craft CMS versions 2 prior to 2.7.10 and 3 prior to 3.2.6. The flaw allowed EXIF data, potentially containing personal or geolocation information, to remain embedded in user-uploaded images even when the system was configured to strip it, exposing this data publicly. Rated Medium severity with a CVSS score of 5.3, this vulnerability is network-exploitable with low attack complexity, leading to a potential loss of confidentiality. While not listed on the KEV catalog or having widespread community discussion, an ExploitDB entry (EDB-47343) indicates the existence of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.2524, < 2.7.10CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.2.6CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.