Description
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advance Search for WooCommerce Cross-Site Scripting (1.0.9)
WordPress Plugin Portfolio by BestWebSoft Cross-Site Scripting (2.39)
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2020-26185)
WordPress Plugin WP Mapa Politico Espana Cross-Site Scripting (3.6.2)
WordPress Plugin Forminator-Contact Form, Payment Form & Custom Form Builder SQL Injection (1.29.2)