Description
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
Remediation
References
Related Vulnerabilities
Elgg URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-11016)
Jenkins Missing Authorization Vulnerability (CVE-2024-43045)
WordPress Plugin All-in-One Event Calendar Multiple Vulnerabilities (1.9)
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-27903)