CVE-2025-23362
CVSS 3.0 Score 6.1 of 10 (medium)
Details
Published Jan 29, 2025
CWE ID 79
Summary
CVE-2025-23362 is a cross-site scripting (XSS) vulnerability affecting the old versions 2.3.2 and 2.4.0 of EXIF Viewer Classic. This issue arises due to the software's improper handling of EXIF meta data within images. When an affected image with maliciously crafted EXIF data is rendered, an attacker can execute arbitrary scripts on the web browser. The vendor has confirmed that the product has been refactored and version 3.0.1 is not vulnerable to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share