CVE-2024-56376

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vanderbilt:redcap:14.9.6:*:*:*:*:*:*:*

History

16 Jan 2025, 21:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de Cross Site Scripting (XSS) almacenado en el mensajero integrado de REDCap 14.9.6 permite a los usuarios autenticados inyectar secuencias de comandos maliciosas en el campo de mensajes. Cuando un usuario hace clic en el mensaje recibido, se ejecuta el payload manipulado, lo que potencialmente permite la ejecución de web scripts arbitrarios.
CPE cpe:2.3:a:vanderbilt:redcap:14.9.6:*:*:*:*:*:*:*
References () https://github.com/ping-oui-no/Vulnerability-Research-CVESS/blob/main/RedCap/CVE-2024-56376/README.md - () https://github.com/ping-oui-no/Vulnerability-Research-CVESS/blob/main/RedCap/CVE-2024-56376/README.md - Exploit, Third Party Advisory
References () https://www.evms.edu/research/resources_services/redcap/redcap_change_log/ - () https://www.evms.edu/research/resources_services/redcap/redcap_change_log/ - Release Notes
First Time Vanderbilt
Vanderbilt redcap

09 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-09 23:15

Updated : 2025-01-16 21:10


NVD link : CVE-2024-56376

Mitre link : CVE-2024-56376

CVE.ORG link : CVE-2024-56376


JSON object : View

Products Affected

vanderbilt

  • redcap
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')