Vulnerabilities > Claroline

DATE CVE VULNERABILITY TITLE RISK
2022-08-25 CVE-2022-37159 Unrestricted Upload of File with Dangerous Type vulnerability in Claroline
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
network
low complexity
claroline CWE-434
critical
9.8
2022-08-25 CVE-2022-37160 Cross-site Scripting vulnerability in Claroline
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user.
network
low complexity
claroline CWE-79
5.4
2022-08-25 CVE-2022-37161 Cross-site Scripting vulnerability in Claroline
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
network
low complexity
claroline CWE-79
6.1
2022-08-25 CVE-2022-37162 Cross-site Scripting vulnerability in Claroline
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS).
network
low complexity
claroline CWE-79
5.4