CVE-2020-27359
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A cross-site scripting (XSS) issue in REDCap 8.11.6 through 9.x before 10 allows attackers to inject arbitrary JavaScript or HTML in the Messenger feature. It was found that the filename of the image or file attached in a message could be used to perform this XSS attack. A user could craft a message and send it to anyone on the platform including admins. The XSS payload would execute on the other account without interaction from the user on several pages.
Un problema de tipo cross-site scripting (XSS) en REDCap versiones 8.11.6 hasta 9.x anteriores a 10, permite a atacantes inyectar JavaScript o HTML arbitrario en la funcionalidad Messenger. Se encontró que el nombre de archivo de la imagen o el archivo adjunto en un mensaje podría ser usado para llevar a cabo este ataque de tipo XSS. Un usuario puede diseñar un mensaje y enviarlo a cualquier persona de la plataforma, incluyendo los administradores. La carga útil XSS podría ser ejecutada en la otra cuenta sin la interacción del usuario en varias páginas
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-20 CVE Reserved
- 2020-10-31 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/seb1055/cve-2020-27358-27359 | Third Party Advisory | |
https://www.ruse.tech/blog/38 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.evms.edu/research/resources_services/redcap/redcap_change_log | 2020-11-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Evms Search vendor "Evms" | Redcap Search vendor "Evms" for product "Redcap" | >= 8.11.6 < 10.0.0 Search vendor "Evms" for product "Redcap" and version " >= 8.11.6 < 10.0.0" | - |
Affected
|