Description In Limesurvey before 3.17.14, admin users can mark other users' notifications as read. Remediation References CVE-2019-16181 Related Vulnerabilities Grafana Improper Authentication Vulnerability (CVE-2018-15727) Oracle Database Server Other Vulnerability (CVE-2002-0567) Apache HTTP Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-10092) WordPress Plugin xPinner Lite Multiple Vulnerabilities (2.2) ReviveAdserver Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-7373) Severity Low Classification CVE-2019-16181 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N Tags Missing Update Known Vulnerabilities