Claroline

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 31
    Known Exploited: 0
    2
    Critical Level Threats
    7
    High Level Threats
    19
    Medium Level Threats
    3
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-37160

    Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user.

    Last Modified: Nov 21, 2024
    Published: Aug 25, 2022

    CVE-2022-37159

    Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.

    Last Modified: Nov 21, 2024
    Published: Aug 25, 2022

    CVE-2022-37161

    Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.

    Last Modified: Nov 21, 2024
    Published: Aug 25, 2022

    CVE-2022-37162

    Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.

    Last Modified: Nov 21, 2024
    Published: Aug 25, 2022

    CVE-2013-4753

    Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.11.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field in an inbox action to messaging/messagebox.php, (2) the "First name" field to auth/profile.php, or (3) the Speakers field in an rqAdd action to calendar/agenda.php.

    Last Modified: Apr 12, 2025
    Published: Dec 26, 2014
    Items Per Page
    Claroline Vulnerabilities & Security CVEs | CVE-DB