Description
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2022-21252 Vulnerability (CVE-2022-21252)
Internet Information Services Other Vulnerability (CVE-1999-0449)
MediaWiki Other Vulnerability (CVE-2023-37300)
WordPress 4.2.x Cross-Domain Flash Injection Vulnerability (4.2 - 4.2.18)
Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-7911)