First published: Thu Aug 25 2022(Updated: )
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Claroline Claroline | <=13.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.