Description
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
Remediation
References
Related Vulnerabilities
Drupal Core 8.x.x Multiple Vulnerabilities (8.0.0 - 8.4.8)
WordPress Plugin Database for Contact Form 7, WPforms, Elementor forms Arbitrary File Upload (1.3.2)
Jboss EAP Missing Release of Memory after Effective Lifetime Vulnerability (CVE-2022-0853)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (3.5.5)