An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. An attacker can exploit this to trick the user that receives the survey into clicking on the field name, which redirects them to a phishing website. Thus, this allows malicious actions to be executed without user consent.
References
Link | Resource |
---|---|
https://github.com/ping-oui-no/Vulnerability-Research-CVESS/blob/main/RedCap/CVE_YYYY/README.md | Broken Link |
Configurations
History
25 Feb 2025, 16:16
Type | Values Removed | Values Added |
---|---|---|
First Time |
Vanderbilt redcap
Vanderbilt |
|
Summary |
|
|
CPE | cpe:2.3:a:vanderbilt:redcap:14.9.6:*:*:*:*:*:*:* | |
References | () https://github.com/ping-oui-no/Vulnerability-Research-CVESS/blob/main/RedCap/CVE_YYYY/README.md - Broken Link |
10 Jan 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-10 22:15
Updated : 2025-02-25 16:16
NVD link : CVE-2025-23111
Mitre link : CVE-2025-23111
CVE.ORG link : CVE-2025-23111
JSON object : View
Products Affected
vanderbilt
- redcap
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')