CVE-2021-42136: XSS
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42136?
CVE-2021-42136 is a stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before version 11.4.0.
How does CVE-2021-42136 affect REDCap?
CVE-2021-42136 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value.
What is the severity of CVE-2021-42136?
CVE-2021-42136 has a severity rating of critical (9/10).
How can the XSS vulnerability in CVE-2021-42136 be exploited?
The XSS vulnerability in CVE-2021-42136 can be exploited by storing malicious JavaScript code as a Missing Data Code value.
How can I mitigate the XSS vulnerability in CVE-2021-42136?
To mitigate the XSS vulnerability in CVE-2021-42136, it is recommended to update REDCap to version 11.4.0 or later.