Claroline 13.5.7 and prior allows an authenticated...
Moderate severity
Unreviewed
Published
Aug 26, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Aug 25, 2022
Published to the GitHub Advisory Database
Aug 26, 2022
Last updated
Feb 1, 2023
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user.
References