PT-2024-31682 · Redcap · Redcap

CVE-2024-45527

·

Published

2024-09-01

·

Updated

2024-09-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: REDCap version 14.7.0
Description: The issue allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via "index.php?logout=1", and can also be used to insert a link to an external phishing website. The impact includes potential data theft and account takeover.
Recommendations: For REDCap version 14.7.0, patch immediately and validate user input to resolve the issue. As a temporary workaround, consider restricting access to the New Project action and validating all user input to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45527

Affected Products

Redcap