Cross-Site Scripting Vulnerability in REDCap by Vanderbilt University
CVE-2019-15127

5.4MEDIUM

Key Information:

Vendor

Vanderbilt

Status
Vendor
CVE Published:
21 August 2019

What is CVE-2019-15127?

The vulnerability in REDCap allows non-administrator accounts to be susceptible to Cross-Site Scripting (XSS) attacks via a compromised CSV data import file on the Data Import Tool page. This flaw could lead to unauthorized execution of scripts under the user's session, compromising sensitive data and user integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.