In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-07-26T03:52:46

Updated: 2024-08-05T00:12:42.809Z

Reserved: 2019-07-25T00:00:00

Link: CVE-2019-14280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-26T04:15:11.760

Modified: 2019-09-02T19:15:10.993

Link: CVE-2019-14280

cve-icon Redhat

No data.