CVE-2020-26713: XSS

Published Jan 12, 2021
·
Updated

REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returned in the response and not escaped leading to the reflected XSS vulnerability. Attackers can exploit vulnerabilities to steal login session information or borrow user rights to perform unauthorized acts.

Affected Software

2 affected components
Vanderbilt REDCap=10.0.20
Vanderbilt REDCap=10.3.4

Event History

Jan 12, 2021
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2020-26713?

CVE-2020-26713 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.

2

How do I fix CVE-2020-26713?

To mitigate CVE-2020-26713, update REDCap to version 10.3.5 or later, which addresses the XSS vulnerability.

3

What impact does CVE-2020-26713 have on affected systems?

Exploiting CVE-2020-26713 allows attackers to execute malicious scripts in the context of user sessions, risking exposure of sensitive information.

4

Which versions of REDCap are affected by CVE-2020-26713?

CVE-2020-26713 affects REDCap versions 10.0.20 and 10.3.4.

5

What is the nature of the vulnerability in CVE-2020-26713?

CVE-2020-26713 is a reflected XSS vulnerability that arises from unsanitized user input being returned in responses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203