Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php, which reveals the path in an error message in some circumstances, as demonstrated by a parameter value containing an XSS sequence.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Claroline 输入验证漏洞
Vulnerability Description
Claroline 1.8.6版本之前的版本允许远程验证管理员可以借助对admin/adminusers.php的sort参数中的一个无效值获得敏感信息。该无效值在某些情况下,通过一条错误的信息泄漏路径信息,例如包含一个XSS序列的参数值。
CVSS Information
N/A
Vulnerability Type
N/A