Reflected XSS Vulnerability in REDCap Alerts & Notifications Feature
CVE-2022-42715
6.1MEDIUM
What is CVE-2022-42715?
A reflected XSS vulnerability has been identified in the REDCap platform prior to version 12.04.18, specifically within the Alerts & Notifications upload feature. This vulnerability allows an attacker to upload a specially crafted CSV file, which triggers the execution of arbitrary JavaScript code in the user’s browser. Consequently, this could lead to session hijacking, data theft, or other malicious activities, making it critical for users to update to a fixed version.