First published: Thu Aug 25 2022(Updated: )
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Claroline Claroline | <=13.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37161 is a vulnerability that affects Claroline 13.5.7 and prior versions, making them vulnerable to Cross Site Scripting (XSS) via SVG file upload.
CVE-2022-37161 has a severity rating of 6.1, which is considered medium.
Claroline versions up to and including 13.5.7 are affected by CVE-2022-37161.
CVE-2022-37161 is associated with CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2022-37161, it is recommended to update Claroline to a version that includes a patch for this vulnerability.