AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-3847

MEDIUM · CVSS 4.8 EPSS 2.22%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-03-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-3847
Severity
MEDIUM
CVSS
4.8
EPSS
2.22%
Java

Original NVD Description

A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users" capability (such as administrators/managers) can access other users' Dashboards, but the JavaScript those other users may have added to their Dashboard was not being escaped when being viewed by the user logging in on their behalf.