CVE-2021-42136
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.
- CVSS 3.1
- 9.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- EPSS
- 4.66% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- vanderbilt/redcap
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/166723/REDCap-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://redcap.med.usc.edu/_shib/assets/ChangeLog_Standard.pdfRelease Notes, Third Party Advisory
- https://www.project-redcap.org/Product
- http://packetstormsecurity.com/files/166723/REDCap-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://redcap.med.usc.edu/_shib/assets/ChangeLog_Standard.pdfRelease Notes, Third Party Advisory
- https://www.project-redcap.org/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.