CVE-2025-23362
NONE EPSS 26.6%
Published Jan 29, 20251y ago · Modified Jun 17, 20262w ago
Published Jan 29, 2025 1y ago
Last Modified Jun 17, 2026 2w ago
Description
The old versions of EXIF Viewer Classic contain a cross-site scripting vulnerability caused by improper handling of EXIF meta data. When an image is rendered and crafted EXIF meta data is processed, an arbitrary script may be executed on the web browser. Versions 2.3.2 and 2.4.0 were reported as vulnerable. According to the vendor, the product has been refactored after those old versions and the version 3.0.1 is not vulnerable.
Threat Intelligence
EPSS Exploit Probability
26.6% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-79 Cross-site Scripting Injection
References 3
- chromewebstore.google.com https://chromewebstore.google.com/detail/exif-viewer-classic/nafpfdcmppffipmhcpkbplhkoiekndck
- exifviewers.com https://exifviewers.com/
- jvn.jp https://jvn.jp/en/jp/JVN05508012/
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.