Description
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Remediation
References
Related Vulnerabilities
LimeSurvey CVE-2019-16181 Vulnerability (CVE-2019-16181)
ProjectSend Insertion of Sensitive Information into Log File Vulnerability (CVE-2019-11492)
PrestaShop CVE-2024-34717 Vulnerability (CVE-2024-34717)
WordPress Plugin WooCommerce Cross-Site Scripting (2.0.17)
SharePoint Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-0932)