CVE-2024-56313

A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the Notes field of a calendar event. When the event is viewed, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*

History

22 Apr 2025, 15:43

Type Values Removed Values Added
CPE cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*
References () https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap - () https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap - Exploit, Third Party Advisory
References () https://www.evms.edu/research/resources_services/redcap/redcap_change_log/ - () https://www.evms.edu/research/resources_services/redcap/redcap_change_log/ - Product
First Time Vanderbilt
Vanderbilt redcap

18 Mar 2025, 14:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

14 Jan 2025, 17:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : unknown

10 Jan 2025, 11:15

Type Values Removed Values Added
Summary (en) A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 15.0.0 allows authenticated users to inject malicious scripts into the Notes field of a calendar event. When the event is viewed, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts. (en) A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scripts into the Notes field of a calendar event. When the event is viewed, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts.

24 Dec 2024, 03:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
Summary
  • (es) Una vulnerabilidad de cross-site scripting (XSS) almacenado en la función Calendario de REDCap hasta la versión 15.0.0 permite a los usuarios autenticados inyectar secuencias de comandos maliciosas en el campo Notas de un evento del calendario. Cuando se visualiza el evento, se ejecuta el payload manipulado, lo que potencialmente permite la ejecución de secuencias de comandos web arbitrarias.

22 Dec 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-22 22:15

Updated : 2025-04-22 15:43


NVD link : CVE-2024-56313

Mitre link : CVE-2024-56313

CVE.ORG link : CVE-2024-56313


JSON object : View

Products Affected

vanderbilt

  • redcap
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')