CVE-2019-3847
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.
Se ha detectado una vulnerabilidad en moodle, en versiones anteriores a la 3.6.3, 3.5.5, 3.4.8 y 3.1.17. Los usuarios con la característica "login as other users" (como los administradores o gerentes/managers) pueden acceder a los dashboards de otros usuarios, pero el JavaScript que esos otros usuarios hayan podido añadir a sus dashboards no se escapaba cuando era visualizado por el usuario que iniciaba sesión en su nombre.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-03-27 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/107489 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3847 | 2022-11-07 | |
https://moodle.org/mod/forum/discuss.php?d=384010#p1547742 | 2022-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | < 3.1.17 Search vendor "Moodle" for product "Moodle" and version " < 3.1.17" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | >= 3.4.0 < 3.4.8 Search vendor "Moodle" for product "Moodle" and version " >= 3.4.0 < 3.4.8" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | >= 3.5.0 < 3.5.5 Search vendor "Moodle" for product "Moodle" and version " >= 3.5.0 < 3.5.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | >= 3.6.0 < 3.6.3 Search vendor "Moodle" for product "Moodle" and version " >= 3.6.0 < 3.6.3" | - |
Affected
|