PoC Index

CVE-2007-4717

LOW 3.5EPSS 3.1%

Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) dir parameter in admin/adminusers.php, the (2) action parameter in admin/advancedUserSearch.php, and the (3) view parameter in admin/campusProblem.php.

CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
3.11% chance of exploitation in the next 30 days, 87th percentile
Published
2007-09-05
Updated
2024-08-07

ExploitDB entries (3)

References

Related