CVE-2020-26220
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
11/11/2020
Last modified:
17/11/2020
Description
toucbase.ai before version 2.0 leaks information by not stripping exif data from images. Anyone with access to the uploaded image of other users could obtain its geolocation, device, and software version data etc (if present. The issue is fixed in version 2.0.
Impact
Base Score 3.x
3.50
Severity 3.x
LOW
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:touchbase.ai_project:touchbase.ai:*:*:*:*:*:*:*:* | 2.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



