Description
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascript code in the 'Location' field of a calendar event.
Remediation
References
Related Vulnerabilities
WordPress Plugin WooCommerce Social Login PHP Object Injection (2.6.2)
WordPress Plugin Contact Form Widget-Contact Query, Form Maker SQL Injection (1.0.9)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.24)
WordPress Plugin Sidekick Multiple Unspecified Vulnerabilities (2.2.1)
WordPress Plugin Rich Table of Contents Cross-Site Scripting (1.3.7)