Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-3847

Опубликовано: 27 мар. 2019
Источник: ubuntu
Приоритет: medium
CVSS2: 3.5
CVSS3: 4.8

Описание

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

DNE

disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

needed

esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/focal

DNE

focal

DNE

Показывать по

3.5 Low

CVSS2

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
около 6 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.

CVSS3: 4.8
debian
около 6 лет назад

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4. ...

CVSS3: 4.8
github
около 3 лет назад

Moodle XSS Vulnerability

3.5 Low

CVSS2

4.8 Medium

CVSS3