CVE-2017-7351: SQL Injection
Published Feb 8, 2018
·Updated
A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.
Affected Software
1 affected component
Vanderbilt REDCap>=7.0.0<7.0.11
Event History
Feb 8, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is CVE-2017-7351?
CVE-2017-7351 is a SQL injection issue in a file upload handler in REDCap 7.x before version 7.0.11.
2
How does CVE-2017-7351 affect REDCap?
CVE-2017-7351 allows an attacker to execute arbitrary SQL queries through a file upload handler in REDCap 7.x before version 7.0.11.
3
What is the severity of CVE-2017-7351?
The severity of CVE-2017-7351 is high with a CVSS score of 8.8.
4
How can I fix CVE-2017-7351?
To fix CVE-2017-7351, upgrade REDCap to version 7.0.11 or later.
5
What is the Common Weakness Enumeration (CWE) for CVE-2017-7351?
The CWE for CVE-2017-7351 is CWE-89, which is for SQL Injection vulnerabilities.