Description
A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the message field. When a user click on the received message, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
14.9.6 (semver)
References
www.evms.edu/...resources_services/redcap/redcap_change_log/
github.com/...VESS/blob/main/RedCap/CVE-2024-56376/README.md