NA

CVE-2022-37159

Published: 25/08/2022 Updated: 27/08/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline

Github Repositories

claroline-CVEs This repo describes several vulns found in Claroline Connect app, in its current version : 1357 RCE via arbitrary file upload (CVE-2022-37159) : githubcom/matthieu-hackwitharts/claroline-CVEs/blob/main/rce/rce_file_uploadmd 'Location' stored XSS (CVE-2022-37162) : githubcom/matthieu-hackwitharts/claroline-CVEs/blob/main/calendar_xs