CVE-2024-56377: XSS
A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the Survey Title field or Survey Instructions. When a user receives a survey and clicks anywhere on the survey page to enter data, the crafted payload (which has been injected into all survey fields) is executed, potentially enabling the execution of arbitrary web scripts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-56377?
CVE-2024-56377 is considered a high severity vulnerability due to its potential for exploitation through stored cross-site scripting.
How do I fix CVE-2024-56377?
To remediate CVE-2024-56377, ensure that input validation and sanitization measures are properly implemented for the Survey Title and Survey Instructions fields.
Who is affected by CVE-2024-56377?
CVE-2024-56377 affects users who utilize REDCap version 14.9.6, specifically those who can access and modify survey titles or instructions.
What type of vulnerability is CVE-2024-56377?
CVE-2024-56377 is classified as a stored cross-site scripting (XSS) vulnerability.
What are the potential risks associated with CVE-2024-56377?
The risks of CVE-2024-56377 include unauthorized script execution, data theft, and potential hijacking of user sessions.