CVE-2023-37798: XSS
A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37798?
CVE-2023-37798 is a stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35.
How does CVE-2023-37798 affect Vanderbilt REDCap?
CVE-2023-37798 allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the project title parameter of Vanderbilt REDCap 13.1.35.
What is the severity of CVE-2023-37798?
CVE-2023-37798 has a severity score of 5.4 (medium).
How can I fix CVE-2023-37798?
To fix CVE-2023-37798, update Vanderbilt REDCap to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-37798?
You can find more information about CVE-2023-37798 on the following websites: [http://redcap.com](http://redcap.com), [http://vanderbilt.com](http://vanderbilt.com), and [https://www.cyderes.com/blog/cve-2023-37798-stored-cross-site-scripting-in-vanderbilt-redcap/](https://www.cyderes.com/blog/cve-2023-37798-stored-cross-site-scripting-in-vanderbilt-redcap/).