3.5
CVSSv2

CVE-2021-42136

Published: 13/04/2022 Updated: 21/04/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 9 | Impact Score: 6 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap prior to 11.4.0 allows remote malicious users to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vanderbilt redcap

Exploits

REDCap versions prior to 1140 suffer from a persistent cross site scripting vulnerability that can be leveraged to escalate privileges ...