Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
redcap vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2019-15127
REDCap prior to 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.
Vanderbilt Redcap
6
CVSSv2
CVE-2019-14937
REDCap prior to 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to...
Vanderbilt Redcap
NA
CVE-2023-37798
A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows malicious users to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter.
Vanderbilt Redcap
3.5
CVSSv2
CVE-2020-27359
A cross-site scripting (XSS) issue in REDCap 8.11.6 up to and including 9.x prior to 10 allows malicious users to inject arbitrary JavaScript or HTML in the Messenger feature. It was found that the filename of the image or file attached in a message could be used to perform this ...
Evms Redcap
1 Github repository
3.5
CVSSv2
CVE-2022-24127
A Stored Cross-Site Scripting (XSS) vulnerability exists in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any user with project management permissions to inject arbitrary code into the project title (app_title) field when editing an existing projec...
Vanderbilt Redcap 12.0.11
3.5
CVSSv2
CVE-2022-24004
A Stored Cross-Site Scripting (XSS) vulnerability exists in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any authenticated user to inject arbitrary code into the messenger title (aka new_title) field when editing an existing conversation. The payload executes...
Vanderbilt Redcap 12.0.11
NA
CVE-2023-38825
SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote malicious user to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php.
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
CVE-2006-4304
CVE-2023-26603
CVE-2024-28327
CVE-2023-50363
CVE-2024-21905
template injection
CVE-2024-3400
cross-site request forgery
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3