An issue was discovered in REDCap 14.9.6. A stored cross...
Moderate severity
Unreviewed
Published
Jan 11, 2025
to the GitHub Advisory Database
•
Updated Jan 11, 2025
Description
Published by the National Vulnerability Database
Jan 10, 2025
Published to the GitHub Advisory Database
Jan 11, 2025
Last updated
Jan 11, 2025
An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name of Survey. When a user receive the survey, if he clicks on the field name, it triggers the XSS payload.
References