Stored Cross-Site Scripting Vulnerability in REDCap Calendar Feature
CVE-2024-56313
5.4MEDIUM
What is CVE-2024-56313?
A vulnerability exists in the Calendar feature of REDCap software, enabling authenticated users to perform stored cross-site scripting (XSS) attacks. This flaw allows users to inject malicious scripts into the Notes field of calendar events. When other users view such an event, the injected scripts are executed in their browsers, which may lead to the execution of unauthorized scripts, potentially compromising user data and application integrity. It is crucial for users of REDCap to apply necessary updates and best security practices to mitigate the risk associated with this vulnerability.