Multiple Stored XSS Vulnerabilities in REDCap by Vanderbilt University
CVE-2019-13029

4.8MEDIUM

Key Information:

Vendor

Vanderbilt

Status
Vendor
CVE Published:
11 July 2019

What is CVE-2019-13029?

REDCap versions prior to 8.10.20 and 9.1.2 contain multiple stored Cross-site Scripting (XSS) vulnerabilities. These issues affect the admin panel and survey system, allowing attackers to inject arbitrary HTML or JavaScript code into the user's web browser. When exploited, this vulnerability can lead to malicious actions being executed in the context of the user, potentially compromising user data and security.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.