CVE-2019-15127: XSS
Published Aug 21, 2019
·Updated
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.
Affected Software
1 affected component
Vanderbilt REDCap<9.3.0
Event History
Aug 21, 2019
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15127?
CVE-2019-15127 has a moderate severity level due to its potential for XSS attacks on non-administrator accounts.
2
How do I fix CVE-2019-15127?
To mitigate CVE-2019-15127, users should upgrade to REDCap version 9.3.0 or later.
3
What impact does CVE-2019-15127 have on REDCap users?
CVE-2019-15127 allows attackers to execute cross-site scripting (XSS) attacks via malicious CSV files during data import.
4
Which versions of REDCap are affected by CVE-2019-15127?
CVE-2019-15127 affects all versions of REDCap before 9.3.0.
5
Who is primarily at risk from CVE-2019-15127?
Non-administrator accounts using the Data Import Tool in REDCap are primarily at risk from CVE-2019-15127.