Cross-Site Request Forgery Vulnerability in REDCap Project Dashboards
CVE-2024-56310
8.8HIGH
What is CVE-2024-56310?
REDCap versions up to and including 15.0.0 contain a vulnerability that exposes users to Cross-Site Request Forgery (CSRF) attacks via the Project Dashboards feature. Due to inadequate CSRF protections, an attacker can manipulate users into clicking on a specially crafted Project Dashboards name, which then sends a malicious logout request. This action unexpectedly terminates the user's session, leading to unauthorized actions without their consent. Safeguarding the logout functionality is crucial to improving overall security and preventing such attacks.