4.8
CVSSv3

CVE-2019-13029

Published: 11/07/2019 Updated: 24/07/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 prior to 8.10.20 and 9 prior to 9.1.2 allow an malicious user to inject arbitrary malicious HTML or JavaScript code into a user's web browser.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vanderbilt redcap

Exploits

# Exploit Title: REDCap < 912 - Cross-Site Scripting # Date: 2019-07-19 # Exploit Author: Dylan GARNAUD & Alexandre ZANNI (pwnby/noraj) - Pentesters from Orange Cyberdefense France # Vendor Homepage: projectredcaporg # Software Link: projectredcaporg # Version: Redcap 9xx before 912 and 8xx before 8102 # ...
REDCap versions prior to 912 suffer from a cross site scripting vulnerability ...