PT-2024-31682 · Redcap · Redcap
CVE-2024-45527
·
Published
2024-09-01
·
Updated
2024-09-03
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
REDCap version 14.7.0
Description:
The issue allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via "index.php?logout=1", and can also be used to insert a link to an external phishing website. The impact includes potential data theft and account takeover.
Recommendations:
For REDCap version 14.7.0, patch immediately and validate user input to resolve the issue. As a temporary workaround, consider restricting access to the New Project action and validating all user input to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redcap