Description
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gallery-Flagallery Photo Portfolio 'flagshow.php' Cross-Site Scripting (1.57)
Drupal Core 4.6.x Cross-Site Scripting (4.6.0 - 4.6.5)
WordPress Plugin AI ChatBot Arbitrary File Deletion (4.9.2)
Oracle Application Server Other Vulnerability (CVE-2002-0947)
WebLogic Improper Input Validation Vulnerability (CVE-2017-15707)