CVE-2019-13029: XSS
Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 allow an attacker to inject arbitrary malicious HTML or JavaScript code into a user's web browser.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13029?
CVE-2019-13029 is a vulnerability in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 before 9.1.2 that allows an attacker to inject malicious HTML or JavaScript code into a user's web browser.
What software versions are affected by CVE-2019-13029?
REDCap 8 before 8.10.20 and 9 before 9.1.2 are affected by CVE-2019-13029.
How severe is CVE-2019-13029?
CVE-2019-13029 has a severity rating of 4.8 (medium).
What is the Common Weakness Enumeration (CWE) associated with CVE-2019-13029?
The Common Weakness Enumeration (CWE) associated with CVE-2019-13029 is CWE-79 (Improper Neutralization of Input During Web Page Generation).
How can I fix CVE-2019-13029?
To fix CVE-2019-13029, update your REDCap software to version 8.10.20 or later for REDCap 8, and version 9.1.2 or later for REDCap 9.