First published: Thu Sep 06 2007(Updated: )
Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information via an invalid value in the sort parameter to admin/adminusers.php, which reveals the path in an error message in some circumstances, as demonstrated by a parameter value containing an XSS sequence.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Claroline Claroline | <=1.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.