Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.6%