Lucene search

K
cvelistMitreCVELIST:CVE-2013-4753
HistoryDec 26, 2014 - 11:00 p.m.

CVE-2013-4753

2014-12-2623:00:00
mitre
www.cve.org
4

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

32.2%

Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.11.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field in an inbox action to messaging/messagebox.php, (2) the β€œFirst name” field to auth/profile.php, or (3) the Speakers field in an rqAdd action to calendar/agenda.php.

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

32.2%

Related for CVELIST:CVE-2013-4753