CVE-2022-42715: XSS
A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger arbitrary JavaScript code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42715?
CVE-2022-42715 has a moderate severity level due to its ability to execute arbitrary JavaScript code through a reflected XSS vulnerability.
How do I fix CVE-2022-42715?
To fix CVE-2022-42715, upgrade REDCap to version 12.4.18 or later.
What versions of REDCap are affected by CVE-2022-42715?
REDCap versions prior to 12.4.18 and versions between 12.5.0 and 12.5.11 are affected by CVE-2022-42715.
What type of attack does CVE-2022-42715 enable?
CVE-2022-42715 enables reflected cross-site scripting (XSS) attacks through the Alerts & Notifications upload feature.
What is the impact of exploiting CVE-2022-42715?
Exploiting CVE-2022-42715 can lead to arbitrary JavaScript execution, potentially compromising user data and application security.