CVE-2022-37162
25.08.2022, 17:15
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
Vendor | Product | Version |
---|---|---|
claroline | claroline | 𝑥 ≤ 13.5.7 |
𝑥
= Vulnerable software versions