Dangerous XSS Bugs in RedCAP Threaten Academic & Scientific Research

Share This Post

Researchers have discovered three cross-site scripting (XSS) vulnerabilities in Research Electronic Data Capture (REDCap), a Web application used for building and managing online surveys and databases for scientific and academic researchers.

The vulnerabilities are tracked as CVE-2024-37394, CVE-2024-37395, and CVE-2024-37396, and “could allow attackers to execute malicious JavaScript code in victims’ browsers, potentially compromising sensitive data,” according to an advisory from Trustwave’s SpiderLabs.

Researchers there identified the vulnerabilities in multiple locations within version 13.1.9 in REDCap, which is popular in universities and scientific institutions for managing studies that contain private, sensitive information. The vulnerable locations in the platform include calendar events, public surveys, and project dashboards.

“Our researchers developed proof-of-concept exploits for each vulnerable location,” said the researchers. “In each case, they were able to inject a simple JavaScript payload that, when triggered, executes an alert displaying the document domain.”

The vulnerabilities could allow threat actors to steal sensitive information, impersonate the victim’s actions, manipulate the REDCap application, and even gain access to protected data.

It’s recommended that users update to REDCap version 14.2.1 or later, where the Vanderbilt University has addressed these bugs, to mitigate these flaws. 

https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blte32ef2932d7a4117/66a95345fd20b827be022197/survey(1800)_Yuri_Arcurs_alamy.jpg?disable=upscale&width=1200&height=630&fit=crop

This post was originally published on this site

More Articles

Article

Navigating SEC Regulations In Cybersecurity And Incident Response

Free video resource for cybersecurity professionals. As 2024 approaches, we all know how vital it is to keep up to date with regulatory changes that affect our work. We get it – it’s a lot to juggle, especially when you’re in the trenches working on an investigation, handling, and responding to incidents.