ZeroHour

CVE-2025-31959

CVSS 3.1
3.5 low
EPSS
<1%p4
Published
()
Modified
Description

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .

Vendors
hcltech
Products
bigfix service management
Weakness
CWE-1230
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.