CVE-2024-56310: CSRF
REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit this by luring users into clicking on a Project Dashboards name that contains the malicious payload, which triggers a logout request and terminates their session. This vulnerability stems from the absence of CSRF protections on the logout functionality, allowing malicious actions to be executed without user consent.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56310?
CVE-2024-56310 has a high severity rating due to its potential to enable Cross-Site Request Forgery (CSRF) attacks.
How do I fix CVE-2024-56310?
To remediate CVE-2024-56310, upgrade to a version of REDCap later than 14.9.6 that addresses this vulnerability.
What are the impacts of CVE-2024-56310?
CVE-2024-56310 can lead to unauthorized logout requests, potentially disrupting user sessions and exposing sensitive information.
Who is affected by CVE-2024-56310?
Users of REDCap versions up to and including 14.9.6 are affected by CVE-2024-56310.
How does CVE-2024-56310 exploit work?
CVE-2024-56310 exploits a vulnerable Project Dashboards name that can trick users into triggering a CSRF attack.