PT-2024-36784 · Redcap · Redcap
Published
2024-12-22
·
Updated
2025-04-22
·
CVE-2024-56313
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
REDCap versions through 14.9.6
Description
A stored cross-site scripting (XSS) vulnerability in the Calendar feature allows authenticated users to inject malicious scripts into the Notes field of a calendar event. When the event is viewed, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.
Recommendations
For versions through 14.9.6, update to a version later than 14.9.6 to resolve the issue. As a temporary workaround, consider restricting access to the Calendar feature or disabling the ability to inject scripts into the Notes field until a patch is available. Avoid using the Notes field in the Calendar feature until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redcap