Reflected XSS Vulnerability in REDCap Alerts & Notifications Feature
CVE-2022-42715

6.1MEDIUM

Key Information:

Vendor

Vanderbilt

Status
Vendor
CVE Published:
12 October 2022

What is CVE-2022-42715?

A reflected XSS vulnerability has been identified in the REDCap platform prior to version 12.04.18, specifically within the Alerts & Notifications upload feature. This vulnerability allows an attacker to upload a specially crafted CSV file, which triggers the execution of arbitrary JavaScript code in the user’s browser. Consequently, this could lead to session hijacking, data theft, or other malicious activities, making it critical for users to update to a fixed version.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.