Stored XSS Vulnerability in REDCap by nonprofit vendor
CVE-2025-23112

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 January 2025

What is CVE-2025-23112?

In REDCap version 14.9.6, a stored cross-site scripting (XSS) flaw enables authenticated users to inject harmful scripts into the Survey field name of the Survey feature. This vulnerability poses significant security risks, as when another user accesses the survey and interacts with the compromised field name, the XSS payload executes, potentially compromising user data and session information.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.