CVE-2017-10961: CSRF
Published Jul 18, 2017
·Updated
REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
Affected Software
1 affected component
Vanderbilt REDCap<=7.5.0
Event History
Jul 18, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10961?
CVE-2017-10961 is classified as a moderate severity vulnerability due to the potential for Cross-Site Request Forgery (CSRF) attacks.
2
How do I fix CVE-2017-10961?
To fix CVE-2017-10961, upgrade your REDCap instance to version 7.5.1 or later.
3
What components are affected by CVE-2017-10961?
CVE-2017-10961 affects the File Repository and File Upload components of REDCap.
4
Is CVE-2017-10961 a remote exploit vulnerability?
Yes, CVE-2017-10961 can be exploited remotely under certain conditions due to its CSRF nature.
5
What kind of attack vector is associated with CVE-2017-10961?
CVE-2017-10961 involves a Cross-Site Request Forgery attack vector that could allow unauthorized deletion of files.