CVE-2020-26713
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returned in the response and not escaped leading to the reflected XSS vulnerability. Attackers can exploit vulnerabilities to steal login session information or borrow user rights to perform unauthorized acts.
REDCap versión 10.3.4, contiene una vulnerabilidad de tipo XSS en la función ToDoList con el parámetro sort. La información enviada por el usuario es inmediatamente devuelta en la respuesta y no se escapa, conllevando a una vulnerabilidad de tipo XSS reflejado. Los atacantes pueden explotar vulnerabilidades para robar información de la sesión de inicio de sesión o tomar prestados derechos de usuario para llevar a cabo actos no autorizados
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-07 CVE Reserved
- 2021-01-12 CVE Published
- 2023-09-28 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/vuongdq54/RedCap | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.evms.edu/research/resources_services/redcap/redcap_change_log | 2021-07-01 | |
https://www.project-redcap.org | 2021-07-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vanderbilt Search vendor "Vanderbilt" | Redcap Search vendor "Vanderbilt" for product "Redcap" | 10.0.20 Search vendor "Vanderbilt" for product "Redcap" and version "10.0.20" | lts |
Affected
| ||||||
Vanderbilt Search vendor "Vanderbilt" | Redcap Search vendor "Vanderbilt" for product "Redcap" | 10.3.4 Search vendor "Vanderbilt" for product "Redcap" and version "10.3.4" | - |
Affected
|