CVE-2024-37396: XSS
A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Notes' field of a calendar event. This could lead to the execution of malicious scripts when the event is viewed. Updating to version 14.2.1 or later is recommended to remediate this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37396?
CVE-2024-37396 has been classified as a medium severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2024-37396?
To mitigate CVE-2024-37396, it is recommended to update REDCap to version 14.2.1 or later, which addresses this vulnerability.
Who is affected by CVE-2024-37396?
REDCap versions prior to 14.2.1 are affected by CVE-2024-37396, particularly users who can access the Calendar function.
What type of vulnerability is CVE-2024-37396?
CVE-2024-37396 is a stored cross-site scripting vulnerability that allows the execution of arbitrary web scripts via a crafted payload.
What can attackers do with CVE-2024-37396?
Attackers exploiting CVE-2024-37396 can execute malicious scripts in the context of authenticated users, potentially compromising their data.