Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) dir parameter in admin/adminusers.php, the (2) action parameter in admin/advancedUserSearch.php, and the (3) view parameter in admin/campusProblem.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4717
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.claroline.net/forum/viewtopic.php?t=13448
- http://osvdb.org/38925
- http://www.claroline.net/wiki/index.php/Changelog_1.8.x#Security
- http://osvdb.org/38927
- http://www.securityfocus.com/bid/25521
- http://secunia.com/advisories/26685
- http://www.vupen.com/english/advisories/2007/3045
- http://osvdb.org/38926
More from claroline
View All →Affected Vendor
claroline
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.