CVE-2025-23112: XSS
An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts into the Survey field name of Survey. When a user receive the survey, if he clicks on the field name, it triggers the XSS payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23112?
CVE-2025-23112 is classified as a moderate severity stored cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-23112?
To fix CVE-2025-23112, upgrade to a patched version of REDCap that addresses this vulnerability.
Who is affected by CVE-2025-23112?
Authenticated users of REDCap 14.9.6 are affected by CVE-2025-23112.
What impact does CVE-2025-23112 have?
CVE-2025-23112 allows authenticated users to inject malicious scripts, potentially leading to session hijacking or data theft.
Where can I find more information about CVE-2025-23112?
Detailed information about CVE-2025-23112 can be found in security advisories or vulnerability databases.