CVE-2024-37396
- EPSS 0.24%
- Veröffentlicht 10.06.2025 00:00:00
- Zuletzt bearbeitet 16.06.2025 15:12:55
A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead ...
CVE-2024-37395
- EPSS 0.18%
- Veröffentlicht 10.06.2025 00:00:00
- Zuletzt bearbeitet 16.06.2025 15:15:48
A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' field...
CVE-2024-37394
- EPSS 0.24%
- Veröffentlicht 10.06.2025 00:00:00
- Zuletzt bearbeitet 16.06.2025 15:17:46
A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text box...
CVE-2025-23113
- EPSS 0.05%
- Veröffentlicht 10.01.2025 22:15:28
- Zuletzt bearbeitet 25.02.2025 16:11:55
An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containing a list of alert configuration. An attacker can send the victim a CSV file containing an H...
CVE-2025-23112
- EPSS 0.12%
- Veröffentlicht 10.01.2025 22:15:27
- Zuletzt bearbeitet 25.02.2025 16:14:20
An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name of Survey. When a user receive the survey, if he clicks on the field name, i...
CVE-2025-23111
- EPSS 0.09%
- Veröffentlicht 10.01.2025 22:15:27
- Zuletzt bearbeitet 25.02.2025 16:16:50
An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. An attacker can exploit this to trick the user that receives the survey into clicking on the field na...
CVE-2025-23110
- EPSS 0.09%
- Veröffentlicht 10.01.2025 22:15:27
- Zuletzt bearbeitet 25.02.2025 16:46:57
An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an upload of a CSV file containing a list of alert configurations. An attacker can send the victim a CSV...
CVE-2024-56377
- EPSS 0.13%
- Veröffentlicht 09.01.2025 23:15:08
- Zuletzt bearbeitet 16.01.2025 21:10:25
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the su...
CVE-2024-56376
- EPSS 0.13%
- Veröffentlicht 09.01.2025 23:15:07
- Zuletzt bearbeitet 16.01.2025 21:10:10
A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, po...
CVE-2024-56314
- EPSS 0.13%
- Veröffentlicht 22.12.2024 22:15:06
- Zuletzt bearbeitet 22.04.2025 15:43:45
A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field of a Project. When a user clicks on the project name to access it, the crafted p...