Vanderbilt

Redcap

40 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.24%
  • Published 10.06.2025 00:00:00
  • Last modified 16.06.2025 15:12:55

A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead ...

Exploit
  • EPSS 0.18%
  • Published 10.06.2025 00:00:00
  • Last modified 16.06.2025 15:15:48

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' field...

Exploit
  • EPSS 0.24%
  • Published 10.06.2025 00:00:00
  • Last modified 16.06.2025 15:17:46

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text box...

  • EPSS 0.05%
  • Published 10.01.2025 22:15:28
  • Last modified 25.02.2025 16:11:55

An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containing a list of alert configuration. An attacker can send the victim a CSV file containing an H...

  • EPSS 0.12%
  • Published 10.01.2025 22:15:27
  • Last modified 25.02.2025 16:14:20

An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name of Survey. When a user receive the survey, if he clicks on the field name, i...

  • EPSS 0.09%
  • Published 10.01.2025 22:15:27
  • Last modified 25.02.2025 16:16:50

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. An attacker can exploit this to trick the user that receives the survey into clicking on the field na...

  • EPSS 0.09%
  • Published 10.01.2025 22:15:27
  • Last modified 25.02.2025 16:46:57

An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an upload of a CSV file containing a list of alert configurations. An attacker can send the victim a CSV...

Exploit
  • EPSS 0.13%
  • Published 09.01.2025 23:15:08
  • Last modified 16.01.2025 21:10:25

A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the su...

Exploit
  • EPSS 0.13%
  • Published 09.01.2025 23:15:07
  • Last modified 16.01.2025 21:10:10

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, po...

Exploit
  • EPSS 0.13%
  • Published 22.12.2024 22:15:06
  • Last modified 22.04.2025 15:43:45

A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field of a Project. When a user clicks on the project name to access it, the crafted p...