Stored XSS Vulnerability in REDCap by nonprofit vendor
CVE-2025-23112
6.1MEDIUM
What is CVE-2025-23112?
In REDCap version 14.9.6, a stored cross-site scripting (XSS) flaw enables authenticated users to inject harmful scripts into the Survey field name of the Survey feature. This vulnerability poses significant security risks, as when another user accesses the survey and interacts with the compromised field name, the XSS payload executes, potentially compromising user data and session information.