CVE-2013-4608: XSS
Published Jun 17, 2013
·Updated
Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View & Descriptive Stats page.
Affected Software
19 affected components
Project-redcap Redcap=4.13.18
Project-redcap Redcap=4.14.5
Project-redcap Redcap=4.14.6
Project-redcap Redcap=4.15.0
Project-redcap Redcap=4.15.1
Project-redcap Redcap=4.15.2
Project-redcap Redcap=4.15.3
Project-redcap Redcap=4.15.4
Project-redcap Redcap=5.0.0
Project-redcap Redcap=5.0.1
Project-redcap Redcap=5.0.2
Project-redcap Redcap=5.0.3
Project-redcap Redcap=5.0.4
Vanderbilt REDCap<=5.0.5
Vanderbilt REDCap=4.14.0
Vanderbilt REDCap=4.14.1
Vanderbilt REDCap=4.14.2
Vanderbilt REDCap=4.14.3
Vanderbilt REDCap=4.14.4
Event History
Jun 17, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4608?
CVE-2013-4608 is considered a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2013-4608?
To fix CVE-2013-4608, upgrade your REDCap installation to version 5.0.6 or later.
3
Who is affected by CVE-2013-4608?
CVE-2013-4608 affects multiple versions of REDCap, specifically versions prior to 5.0.6.
4
What type of vulnerability is CVE-2013-4608?
CVE-2013-4608 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2013-4608?
Attackers can exploit CVE-2013-4608 to inject arbitrary web scripts or HTML into the affected REDCap pages.