CVE-2024-56312: XSS
A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the name field of a Project Dashboard. When a user clicks on the project Dashboard name, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56312?
CVE-2024-56312 is classified as a stored cross-site scripting (XSS) vulnerability, which can have high impact depending on the exploit.
How do I fix CVE-2024-56312?
To fix CVE-2024-56312, upgrade REDCap Project Dashboard to a version higher than 14.9.6.
What does CVE-2024-56312 allow attackers to do?
CVE-2024-56312 allows authenticated users to inject malicious scripts into the Project Dashboard name field.
Who is affected by CVE-2024-56312?
CVE-2024-56312 affects users of the REDCap Project Dashboard software version 14.9.6 and below.
When was CVE-2024-56312 reported?
CVE-2024-56312 was reported recently and pertains to vulnerabilities present in REDCap versions up to 14.9.6.