CVE-2022-42715
12.10.2022, 13:15
A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger arbitrary JavaScript code execution.
Vendor | Product | Version |
---|---|---|
vanderbilt | redcap | 𝑥 < 12.4.18 |
vanderbilt | redcap | 12.5.0 ≤ 𝑥 < 12.5.11 |
𝑥
= Vulnerable software versions
References