PT-2022-16481 · Redcap · Redcap

Published

2022-06-15

·

Updated

2022-06-24

·

CVE-2022-24127

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions REDCap version 12.0.11
Description A Stored Cross-Site Scripting issue was discovered in the edit project settings.php file. This issue allows users with project management permissions to inject arbitrary code into the app title field when editing a project. The injected code is then reflected within the title tag of the page.
Recommendations For REDCap version 12.0.11, consider restricting access to the edit project settings.php file until a fix is available, and avoid using the app title field for user-inputted data to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24127

Affected Products

Redcap