Description
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
Remediation
References
Related Vulnerabilities
WordPress Plugin Themify Portfolio Post Cross-Site Scripting (1.2.0)
LimeSurvey Incorrect Default Permissions Vulnerability (CVE-2019-16183)
Dot CMS Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-11466)
WordPress Plugin User Photo 'user-photo.php' Arbitrary File Upload (0.9.4)