CVE-2023-37361: SQL Injection
Published Jul 25, 2023
·Updated
REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, apptitle, or randomization.
Affected Software
2 affected components
Vanderbilt REDCap<12.3.2
Vanderbilt REDCap<12.0.26
Event History
Jul 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-37361?
CVE-2023-37361 has been rated as a critical severity SQL Injection vulnerability.
2
How do I fix CVE-2023-37361?
To fix CVE-2023-37361, update REDCap to version 12.3.3 or later.
3
What versions of REDCap are affected by CVE-2023-37361?
CVE-2023-37361 affects REDCap versions 12.0.26 LTS and 12.3.2 Standard.
4
What types of input can lead to SQL Injection in CVE-2023-37361?
CVE-2023-37361 is vulnerable through inputs like scheduling, repeatforms, purpose, app_title, or randomization.
5
What are the risks associated with CVE-2023-37361?
Exploitation of CVE-2023-37361 may allow attackers to execute arbitrary SQL queries against the database.