2022-08-25 16:19:42
mitre
PUBLISHED
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the Location field of a calendar event.