vendor:
Redcap
by:
Kendrick Lam
9
CVSS
CRITICAL
Stored Cross-Site Scripting
79
CWE
Product Name: Redcap
Affected Version From: 11.3.2009
Affected Version To: 11.4.2000
Patch Exists: YES
Related CWE: CVE-2021-42136
CPE: a:project_redcap:redcap
Platforms Tested: 11.2.2005
2021
REDCap 11.3.9 – Stored Cross-Site Scripting
It was possible to store JavaScript as values for Missing Data Codes. The payload will escalate a regular user's privileges, if viewed by an account with permission to change privileges (such as an administrator).
Mitigation:
Ensure that user input is properly sanitized and validated before being stored in the database.