CVE-2017-10961
https://notcve.org/view.php?id=CVE-2017-10961
REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components. REDCap anterior a versión 7.5.1, presenta un problema de tipo CSRF en la función deletion de los componentes File Repository y File Upload. • https://community.projectredcap.org/articles/13/changelog-standard-release.html https://gist.github.com/jordanpotti/fef4f1ada404d5ba7f88ab42e93cdaae • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2017-10962
https://notcve.org/view.php?id=CVE-2017-10962
REDCap before 7.5.1 has XSS via the query string. REDCap anterior a versión 7.5.1, presenta un problema de tipo XSS por medio de la cadena de consulta. • https://community.projectredcap.org/articles/13/changelog-standard-release.html https://gist.github.com/jordanpotti/fef4f1ada404d5ba7f88ab42e93cdaae • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-6566
https://notcve.org/view.php?id=CVE-2012-6566
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad Cross-site scripting (XSS) en REDCap anterior a v4.14.2 permite a atacantes remotos a inyectar secuencias de comandos Web o HTML a través de vectores no especificados. • http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-6567
https://notcve.org/view.php?id=CVE-2012-6567
REDCap before 4.14.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the logic of a custom rule. REDCap anterior a v4.14.0 permite a usuarios remotos autenticados ejecutar código arbitrario a través de metacaracteres de shell en la lógica de una regla personalizada • http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf • CWE-20: Improper Input Validation •
CVE-2013-4609
https://notcve.org/view.php?id=CVE-2013-4609
REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call. REDCap anterior a v5.0.4 y v5.1.x anterior a v5.1.3 no rechaza cierta sintaxis no documentada dentro de la lógica de bifurcación y cálculos, lo que permite a usuarios autenticados remotamente evitar las restricciones de acceso establecidas a través de (1) el Online Designer o (2) el Data Dictionary Upload, como se demostró por una llamada eval. • http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf • CWE-264: Permissions, Privileges, and Access Controls •