NA

CVE-2022-37162

Published: 25/08/2022 Updated: 27/08/2022
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

claroline claroline

Github Repositories

claroline-CVEs This repo describes several vulns found in Claroline Connect app, in its current version : 1357 RCE via arbitrary file upload (CVE-2022-37159) : githubcom/matthieu-hackwitharts/claroline-CVEs/blob/main/rce/rce_file_uploadmd 'Location' stored XSS (CVE-2022-37162) : githubcom/matthieu-hackwitharts/claroline-CVEs/blob/main/calendar_xs