Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Claroline CRITICAL 9.8
CVE-2022-37159EPSS 25%

Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.

Fix: after 13.5.7
Fix from $2,300 2022-08-25
Claroline MEDIUM 6.1
CVE-2022-37161

Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.

Fix: after 13.5.7
Fix from $1,600 2022-08-25
Claroline MEDIUM 5.4
CVE-2022-37160

Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the X…

Fix: after 13.5.7
Fix from $1,600 2022-08-25
Claroline MEDIUM 5.4
CVE-2022-37162

Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascri…

Fix: after 13.5.7
Fix from $1,600 2022-08-25
Claroline MEDIUM 5.0
CVE-2011-3716

Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a…

No fix yet
Fix from $1,600 2011-09-23
Claroline MEDIUM 5.8
CVE-2008-3262

Cross-site request forgery (CSRF) vulnerability in Claroline before 1.8.10 allows remote attackers to change passwords, related to lack of a requirem…

Fix: after 1.8.9
Fix from $1,600 2008-07-22
Claroline MEDIUM 5.1
CVE-2007-4718EPSS 7%

Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary loca…

Fix: after 1.8.5
Fix from $1,600 2007-09-05
Claroline HIGH 7.5
CVE-2006-7048

Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) claro…

Mitigation only
Fix from $1,950 2007-02-24
Claroline HIGH 7.5
CVE-2006-5256

PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitra…

Fix: after 1.8.0
Fix from $1,950 2006-10-12
Claroline MEDIUM 5.1
CVE-2006-4844EPSS 10%

PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products…

Fix: after 1.7.7
Fix from $1,600 2006-09-19
Claroline MEDIUM 5.1
CVE-2006-2868EPSS 11%

Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the includePa…

No fix yet
Fix from $1,600 2006-06-06
Claroline MEDIUM 6.8
CVE-2006-2284EPSS 7%

Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) claro…

Patch available
Fix from $1,600 2006-05-10
Claroline HIGH 7.5
CVE-2006-1594

Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and earlier allow remote attackers to use ".." (dot dot) seq…

Fix: after 1.7.4
Fix from $1,950 2006-04-03
Claroline HIGH 7.5
CVE-2006-1596

PHP remote file inclusion vulnerability in learnPath/include/scormExport.inc.php in Claroline 1.7.4 and earlier allows remote attackers to execute ar…

No fix yet
Fix from $1,950 2006-04-03
Claroline HIGH 10.0
CVE-2006-0411

claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack ses…

Mitigation only
Fix from $1,950 2006-01-25
Claroline HIGH 7.5
CVE-2005-1375

Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arb…

Patch available
Fix from $1,950 2005-05-03
Claroline HIGH 7.5
CVE-2005-1376

Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possi…

Patch available
Fix from $1,950 2005-05-03
Claroline HIGH 7.5
CVE-2005-1377

Multiple PHP remote file inclusion vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to…

Patch available
Fix from $1,950 2005-05-03
Claroline MEDIUM 6.8
CVE-2005-1374

Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers t…

Patch available
Fix from $1,600 2005-05-03