Lucene search

K
cvelistMitreCVELIST:CVE-2021-42136
HistoryApr 13, 2022 - 3:32 p.m.

CVE-2021-42136

2022-04-1315:32:56
mitre
www.cve.org
4
vulnerability
cross-site scripting
redcap
missing data codes
remote attack
javascript
cross-site request forgery
privilege escalation

AI Score

8.7

Confidence

High

EPSS

0.13

Percentile

95.6%

A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client’s browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.

AI Score

8.7

Confidence

High

EPSS

0.13

Percentile

95.6%

Related for CVELIST:CVE-2021-42136