Lucene search

K
cveMitreCVE-2020-26713
HistoryJan 12, 2021 - 3:15 p.m.

CVE-2020-26713

2021-01-1215:15:13
CWE-79
mitre
web.nvd.nist.gov
23
cve-2020-26713
redcap
xss
vulnerability
todolist
sort parameter
reflected xss

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

47.8%

REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returned in the response and not escaped leading to the reflected XSS vulnerability. Attackers can exploit vulnerabilities to steal login session information or borrow user rights to perform unauthorized acts.

Affected configurations

Nvd
Node
vanderbiltredcapMatch10.0.20lts
OR
vanderbiltredcapMatch10.3.4-
VendorProductVersionCPE
vanderbiltredcap10.0.20cpe:2.3:a:vanderbilt:redcap:10.0.20:*:*:*:lts:*:*:*
vanderbiltredcap10.3.4cpe:2.3:a:vanderbilt:redcap:10.3.4:*:*:*:-:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

47.8%

Related for CVE-2020-26713