Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2020-27358

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export their conversation threads as CSV) allows non-privileged users to export one another's conversation threads by changing the thread_id parameter in the request to the endpoint Messenger/messenger_download_csv.php?title=Hey&thread_id={THREAD_ID}.
Attacker Value
Unknown

CVE-2014-6311

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.
Attacker Value
Unknown

CVE-2019-17121

Disclosure Date: October 04, 2019 (last updated November 27, 2024)
REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.
Attacker Value
Unknown

CVE-2019-15127

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.
0
Attacker Value
Unknown

CVE-2019-14937

Disclosure Date: August 17, 2019 (last updated November 27, 2024)
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
0
Attacker Value
Unknown

CVE-2019-13029

Disclosure Date: July 11, 2019 (last updated November 27, 2024)
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker to inject arbitrary malicious HTML or JavaScript code into a user's web browser.
0
Attacker Value
Unknown

CVE-2017-7351

Disclosure Date: February 08, 2018 (last updated November 26, 2024)
A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.
0
Attacker Value
Unknown

CVE-2017-10962

Disclosure Date: July 18, 2017 (last updated November 26, 2024)
REDCap before 7.5.1 has XSS via the query string.
0
Attacker Value
Unknown

CVE-2017-10961

Disclosure Date: July 18, 2017 (last updated November 26, 2024)
REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
0
Attacker Value
Unknown

CVE-2012-6564

Disclosure Date: June 17, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0