Lucene search

K
nvd[email protected]NVD:CVE-2023-37798
HistorySep 07, 2023 - 7:15 p.m.

CVE-2023-37798

2023-09-0719:15:47
CWE-79
web.nvd.nist.gov
2
vanderbilt
redcap
stored xss
project creation
vulnerability
web scripts
html
crafted payload

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.7%

A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter.

Affected configurations

Nvd
Node
vanderbiltredcapRange13.1.35
VendorProductVersionCPE
vanderbiltredcap*cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

29.7%

Related for NVD:CVE-2023-37798