Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Claroline 跨站脚本漏洞
Vulnerability Description
Claroline是Claroline开源的一个开源学习管理系统。 Claroline 13.5.7版本及之前版本存在跨站脚本漏洞,该漏洞源于易受跨站脚本 (XSS) 攻击。攻击者利用该漏洞在日历事件的“Location”字段中添加任意 javascript 代码来获取 javascript 代码执行。
CVSS Information
N/A
Vulnerability Type
N/A