Cross-Site Request Forgery Vulnerability in REDCap Project Dashboards
CVE-2024-56310

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
22 December 2024

What is CVE-2024-56310?

REDCap versions up to and including 15.0.0 contain a vulnerability that exposes users to Cross-Site Request Forgery (CSRF) attacks via the Project Dashboards feature. Due to inadequate CSRF protections, an attacker can manipulate users into clicking on a specially crafted Project Dashboards name, which then sends a malicious logout request. This action unexpectedly terminates the user's session, leading to unauthorized actions without their consent. Safeguarding the logout functionality is crucial to improving overall security and preventing such attacks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.