Show filters
31 Total Results
Displaying 1-10 of 31
Sort by:
Attacker Value
Unknown
CVE-2022-37162
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
0
Attacker Value
Unknown
CVE-2022-37161
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
0
Attacker Value
Unknown
CVE-2022-37160
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user.
0
Attacker Value
Unknown
CVE-2022-37159
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
0
Attacker Value
Unknown
CVE-2013-4753
Disclosure Date: December 26, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.11.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field in an inbox action to messaging/messagebox.php, (2) the "First name" field to auth/profile.php, or (3) the Speakers field in an rqAdd action to calendar/agenda.php.
0
Attacker Value
Unknown
CVE-2013-6267
Disclosure Date: December 05, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.11.9 allow remote attackers to inject arbitrary web script or HTML via the (1) box parameter to messaging/messagebox.php, cidToEdit parameter to (2) adminregisteruser.php or (3) admin_user_course_settings.php in admin/, (4) module_id parameter to admin/module/module.php, or (5) offset parameter to admin/right/profile_list.php.
0
Attacker Value
Unknown
CVE-2011-3716
Disclosure Date: September 23, 2011 (last updated October 04, 2023)
Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by work/connector/linker.cnr.php and certain other files.
0
Attacker Value
Unknown
CVE-2009-1907
Disclosure Date: June 04, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in claroline/linker/notfound.php in Claroline 1.8.11 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.
0
Attacker Value
Unknown
CVE-2008-3315
Disclosure Date: July 25, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web script or HTML via the (1) query string to (a) announcements/messages.php; (b) lostPassword.php and (c) profile.php in auth/; (d) calendar/myagenda.php; (e) group/group.php; (f) learningPath.php, (g) learningPathList.php, and (h) module.php in learnPath/; (i) phpbb/index.php; (j) courseLog.php, (k) course_access_details.php, (l) delete_course_stats.php, (m) userLog.php, and (n) user_access_details.php in tracking/; (o) user/user.php; and (p) user/userInfo.php; the (2) view parameter to (q) tracking/courseLog.php; and the (3) toolId parameter to (r) tracking/toolaccess_details.php. NOTE: this may overlap CVE-2006-3257 and CVE-2005-1374.
0
Attacker Value
Unknown
CVE-2008-3261
Disclosure Date: July 22, 2008 (last updated October 04, 2023)
Open redirect vulnerability in claroline/redirector.php in Claroline before 1.8.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
0