CVE-2017-10962: XSS
Published Jul 18, 2017
·Updated
REDCap before 7.5.1 has XSS via the query string.
Affected Software
1 affected component
Vanderbilt REDCap<=7.5.0
Event History
Jul 18, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10962?
CVE-2017-10962 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-10962?
To fix CVE-2017-10962, upgrade REDCap to version 7.5.1 or later.
3
What kind of vulnerability is CVE-2017-10962?
CVE-2017-10962 is a cross-site scripting (XSS) vulnerability that can be exploited via the query string.
4
Which versions of REDCap are affected by CVE-2017-10962?
REDCap versions before 7.5.1, specifically up to and including 7.5.0, are affected by CVE-2017-10962.
5
Is user data at risk due to CVE-2017-10962?
Yes, user data may be at risk due to the potential for attackers to execute malicious scripts through the XSS vulnerability in CVE-2017-10962.