CVE-2012-6564: XSS
Published Jun 17, 2013
·Updated
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
5 affected components
Vanderbilt REDCap<=4.14.4
Vanderbilt REDCap=4.14.0
Vanderbilt REDCap=4.14.1
Vanderbilt REDCap=4.14.2
Vanderbilt REDCap=4.14.3
Event History
Jun 17, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6564?
CVE-2012-6564 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2012-6564?
To fix CVE-2012-6564, update REDCap to version 4.14.5 or later.
3
What types of attacks can CVE-2012-6564 allow?
CVE-2012-6564 allows remote attackers to inject arbitrary web scripts or HTML, facilitating cross-site scripting attacks.
4
Which versions of REDCap are affected by CVE-2012-6564?
REDCap versions before 4.14.5, specifically 4.14.0 to 4.14.4, are affected by CVE-2012-6564.
5
Can CVE-2012-6564 be exploited without user interaction?
Yes, CVE-2012-6564 can be exploited remotely and does not require user interaction.