Vanderbilt

REDCap

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 02.01.2026 15:15:56
  • Zuletzt bearbeitet 12.01.2026 15:27:42

REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 10.06.2025 00:00:00
  • Zuletzt bearbeitet 16.06.2025 15:12:55

A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead ...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 10.06.2025 00:00:00
  • Zuletzt bearbeitet 16.06.2025 15:15:48

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Survey Title' and 'Survey Instructions' field...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 10.06.2025 00:00:00
  • Zuletzt bearbeitet 16.06.2025 15:17:46

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text box...

  • EPSS 0.05%
  • Veröffentlicht 10.01.2025 22:15:28
  • Zuletzt bearbeitet 25.02.2025 16:11:55

An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file containing a list of alert configuration. An attacker can send the victim a CSV file containing an H...

  • EPSS 0.12%
  • Veröffentlicht 10.01.2025 22:15:27
  • Zuletzt bearbeitet 25.02.2025 16:14:20

An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name of Survey. When a user receive the survey, if he clicks on the field name, i...

  • EPSS 0.09%
  • Veröffentlicht 10.01.2025 22:15:27
  • Zuletzt bearbeitet 25.02.2025 16:16:50

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. An attacker can exploit this to trick the user that receives the survey into clicking on the field na...

  • EPSS 0.09%
  • Veröffentlicht 10.01.2025 22:15:27
  • Zuletzt bearbeitet 25.02.2025 16:46:57

An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an upload of a CSV file containing a list of alert configurations. An attacker can send the victim a CSV...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 09.01.2025 23:15:08
  • Zuletzt bearbeitet 16.01.2025 21:10:25

A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the su...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 09.01.2025 23:15:07
  • Zuletzt bearbeitet 16.01.2025 21:10:10

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, po...