CVE-2012-6566: XSS
Published Jun 17, 2013
·Updated
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
2 affected components
Vanderbilt REDCap<=4.14.1
Vanderbilt REDCap=4.14.0
Event History
Jun 17, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6566?
CVE-2012-6566 has been classified as a medium-severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2012-6566?
To fix CVE-2012-6566, upgrade REDCap to version 4.14.2 or later.
3
What impact does CVE-2012-6566 have on my REDCap installation?
CVE-2012-6566 may allow remote attackers to inject arbitrary web scripts or HTML, compromising the security of your application.
4
Which versions of REDCap are affected by CVE-2012-6566?
REDCap versions before 4.14.2, specifically 4.14.1 and 4.14.0, are affected by CVE-2012-6566.
5
Is there a workaround for CVE-2012-6566 until I can upgrade?
There are no officially recommended workarounds for CVE-2012-6566, and upgrading is the best method to mitigate the vulnerability.