First published: Wed Sep 05 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) dir parameter in admin/adminusers.php, the (2) action parameter in admin/advancedUserSearch.php, and the (3) view parameter in admin/campusProblem.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Claroline Claroline | <=1.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4717 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
CVE-2007-4717 affects all versions of Claroline prior to 1.8.6.
To fix CVE-2007-4717, upgrade Claroline to version 1.8.6 or later.
CVE-2007-4717 allows remote authenticated administrators to perform cross-site scripting attacks.
Yes, CVE-2007-4717 requires an authenticated user to exploit the vulnerabilities.