CVE-2024-56376

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vanderbilt:redcap:14.9.6:*:*:*:*:*:*:*

History

16 Jan 2025, 21:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de Cross Site Scripting (XSS) almacenado en el mensajero integrado de REDCap 14.9.6 permite a los usuarios autenticados inyectar secuencias de comandos maliciosas en el campo de mensajes. Cuando un usuario hace clic en el mensaje recibido, se ejecuta el payload manipulado, lo que potencialmente permite la ejecución de web scripts arbitrarios.
References () https://github.com/ping-oui-no/Vulnerability-Research-CVESS/blob/main/RedCap/CVE-2024-56376/README.md - () https://github.com/ping-oui-no/Vulnerability-Research-CVESS/blob/main/RedCap/CVE-2024-56376/README.md - Exploit, Third Party Advisory
References () https://www.evms.edu/research/resources_services/redcap/redcap_change_log/ - () https://www.evms.edu/research/resources_services/redcap/redcap_change_log/ - Release Notes
CPE cpe:2.3:a:vanderbilt:redcap:14.9.6:*:*:*:*:*:*:*
First Time Vanderbilt redcap
Vanderbilt

09 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-09 23:15

Updated : 2025-01-16 21:10


NVD link : CVE-2024-56376

Mitre link : CVE-2024-56376

CVE.ORG link : CVE-2024-56376


JSON object : View

Products Affected

vanderbilt

  • redcap
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')