3.5
CVSSv2

CVE-2022-24127

Published: 15/06/2022 Updated: 24/06/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A Stored Cross-Site Scripting (XSS) vulnerability exists in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any user with project management permissions to inject arbitrary code into the project title (app_title) field when editing an existing project. The payload is then reflected within the title tag of the page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vanderbilt redcap 12.0.11