CVE-2023-38825: SQL Injection
Published Mar 6, 2024
·Updated
SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php.
Affected Software
2 affected components
Vanderbilt REDCap<13.8.0
Vanderbilt REDCap<13.8.0
Event History
Mar 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 21, 2024
Data Sourced
via NVD·02:48 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-38825?
CVE-2023-38825 is considered to be of high severity due to its potential to expose sensitive information.
2
How do I fix CVE-2023-38825?
To fix CVE-2023-38825, upgrade Vanderbilt REDCap to version 13.8.0 or later.
3
What type of attack does CVE-2023-38825 allow?
CVE-2023-38825 allows a remote attacker to perform SQL injection through the password reset mechanism.
4
Which software versions are affected by CVE-2023-38825?
CVE-2023-38825 affects Vanderbilt REDCap versions before 13.8.0.
5
What components are involved in CVE-2023-38825?
CVE-2023-38825 involves the MyCapMobileApp and update.php component in Vanderbilt REDCap.