CVE-2025-23112

An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name of Survey. When a user receive the survey, if he clicks on the field name, it triggers the XSS payload.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vanderbilt:redcap:14.9.6:*:*:*:*:*:*:*

History

25 Feb 2025, 16:14

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en REDCap 14.9.6. Una vulnerabilidad de cross-site scripting almacenado permite que los usuarios autenticados inyecten scripts maliciosos en el nombre del campo de la encuesta. Cuando un usuario recibe la encuesta, si hace clic en el nombre del campo, se activa el payload XSS.
First Time Vanderbilt redcap
Vanderbilt
References () https://github.com/ping-oui-no/Vulnerability-Research-CVESS/blob/main/RedCap/CVE_ZZZZ/README.md - () https://github.com/ping-oui-no/Vulnerability-Research-CVESS/blob/main/RedCap/CVE_ZZZZ/README.md - Broken Link
CPE cpe:2.3:a:vanderbilt:redcap:14.9.6:*:*:*:*:*:*:*

10 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-10 22:15

Updated : 2025-02-25 16:14


NVD link : CVE-2025-23112

Mitre link : CVE-2025-23112

CVE.ORG link : CVE-2025-23112


JSON object : View

Products Affected

vanderbilt

  • redcap
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')