Description
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the XSS vulnerability present in several upload forms and a javascript request to the present API, it is possible to trigger the creation of a user with administrative rights by opening an SVG file as an administrator user.
Remediation
References
Related Vulnerabilities
WordPress 2.6.2 Remote Code Execution Vulnerability (0.70 - 2.6.2)
Squid Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-8449)
WordPress Plugin MemberSonic Lite Security Bypass (1.2)
WordPress Plugin Weekly Schedule Cross-Site Scripting (3.4.2)
WordPress Plugin Weaver Show Posts Cross-Site Scripting (1.6)