Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

EXIF Geolocation Data Not Stripped From Uploaded Images #186

Closed
rahadchowdhury opened this issue Apr 3, 2023 · 0 comments
Closed

EXIF Geolocation Data Not Stripped From Uploaded Images #186

rahadchowdhury opened this issue Apr 3, 2023 · 0 comments
Labels
bug Something isn't working

Comments

@rahadchowdhury
Copy link

Describe the bug
When a user uploads an image in "SLiMS 9 Bulian official source code", the uploaded image’s EXIF Geolocation Data does not gets stripped. As a result, anyone can get sensitive information of "SLiMS 9 Bulian official source code" users like their Geolocation, their Device information like Device Name, Version, Software & Software version used etc.

CMS Version:
v9.5.2

Affected URL:
http://127.0.0.1/bulian/admin/index.php?mod=membership

To Reproduce
Steps to reproduce the behavior:

  1. Got to Github ( https://github.com/ianare/exif-samples/tree/master/jpg)
  2. There are lot of images having resolutions (i.e 1280 * 720 ) , and also whith different MB’s .
    login your admin panel and membership menu and upload photo in any member profile.
  3. see the path of uploaded image ( Either by right click on image then copy image address OR right click, inspect the image, the URL will come in the inspect , edit it as html )
  4. open it (https://www.verexif.com/en/index.php)
  5. See whether is that still showing exif data , if it is then Report it.

Proof Of Concept:
You can see the Proof of Concept. which I've attached screenshots and video to confirm the vulnerability.

Screenshots
screenshot1
screenshot2
screenshot_2
screenshot3

Video

video.mp4

Desktop (please complete the following information):

  • OS: Windows 10
  • Browser: Google Chrome

Impact
This vulnerability is CRITICAL and impacts all the "SLiMS 9 Bulian official source code" customer base. This vulnerability violates the privacy of a User and shares sensitive information of the user who uploads an image on SLiMS 9 Bulian official.

Let me know if any further info is required.

Thanks & Regards
Rahad Chowdhury
Cyber Security Specialist
https://www.linkedin.com/in/rahadchowdhury

@rahadchowdhury rahadchowdhury added the bug Something isn't working label Apr 3, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants