PT-2019-13087 · Vanderbilt University · Redcap

Alexandre Zanni

+1

·

Published

2019-07-11

·

Updated

2025-03-19

·

CVE-2019-13029

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions REDCap versions 8.0.0 through 8.10.19 REDCap versions 9.0.0 through 9.1.1
Description The issue concerns multiple stored Cross-site scripting (XSS) problems in the admin panel and survey system. An attacker can inject arbitrary malicious HTML or JavaScript code into a user's web browser.
Recommendations For REDCap versions 8.0.0 through 8.10.19, update to version 8.10.20 or later. For REDCap versions 9.0.0 through 9.1.1, update to version 9.1.2 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13029

Affected Products

Redcap