CVE-2012-6565: XSS
Published Jun 17, 2013
·Updated
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary web script or HTML via uppercase characters in JavaScript events within user-defined labels.
Affected Software
3 affected components
Vanderbilt REDCap<=4.14.2
Vanderbilt REDCap=4.14.0
Vanderbilt REDCap=4.14.1
Event History
Jun 17, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6565?
CVE-2012-6565 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2012-6565?
To fix CVE-2012-6565, upgrade REDCap to version 4.14.3 or later.
3
Who is affected by CVE-2012-6565?
CVE-2012-6565 affects users of REDCap versions prior to 4.14.3, particularly those who can define labels.
4
What does CVE-2012-6565 allow an attacker to do?
CVE-2012-6565 allows an attacker to inject arbitrary web scripts or HTML through user-defined labels.
5
Is CVE-2012-6565 a persistent vulnerability?
CVE-2012-6565 can create security risks until the affected software is updated, making it persistent until fixed.