winget install --id szTheory.exifcleaner
About ExifCleaner
Desktop app to clean metadata from images, videos, PDFs, and other files.
What's new in 3.6.0
Security - Fix for XSS and Electron reverse shell vulnerabilities by sanitizing exiftool HTML output in the UI. To take advantage of this, an attacker would have had to write image metadata containing malicious script code to a file that you then download and run through ExifCleaner. Proofs of concept:
Version history
| Version | Updated | Notes |
|---|---|---|
| 3.6.0 | Unknown | Security - Fix for XSS and Electron reverse shell vulnerabilities by sanitizing exiftool HTML output in the UI. To take advantage of this, an attacker would have had to write image metadata containing malicious script co... |
| 3.5.1 | Unknown | No notes |
| 3.5.0 | Unknown | No notes |
| 3.4.0 | Unknown | No notes |
| 3.3.1 | Unknown | No notes |
| 3.2.0 | Unknown | No notes |
| 3.1.0 | Unknown | No notes |