216.73.217.24

CVE-2024-37394

· Published 10/06/2025 18:15 · Modified 11/06/2025 15:15

Labels: CVE-2024-37394 2025-06-10CVE-2024-37394CWE-79[email protected]

Essential information

Published
10/06/2025 18:15
Modified
11/06/2025 15:15
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVSS metrics

Description

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web script or HTML by injecting a crafted payload into the 'Dashboard title' and 'Dashboard content' text boxes. This can lead to the execution of malicious scripts when the dashboard is viewed. Users are recommended to update to version 14.2.1 or later to mitigate this vulnerability.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
redcap / redcap cpe:2.3:a:redcap:redcap:<13.1.9:*:*:*:*:*:*:*
redcap / redcap cpe:2.3:a:redcap:redcap:<14.2.1:*:*:*:*:*:*:*

References