HomeCII/OTXSS Vulnerabilities in RedCAP Pose a Risk to Academic & Scientific Research

XSS Vulnerabilities in RedCAP Pose a Risk to Academic & Scientific Research

Published on

spot_img

Researchers recently uncovered three cross-site scripting (XSS) vulnerabilities in Research Electronic Data Capture (REDCap), a widely used web application designed for creating and managing online surveys and databases for scientific and academic research purposes.

These vulnerabilities, known as CVE-2024-37394, CVE-2024-37395, and CVE-2024-37396, have the potential to enable malicious actors to execute harmful JavaScript code within victims’ browsers, ultimately putting sensitive data at risk. Trustwave’s SpiderLabs issued an advisory highlighting the severity of these vulnerabilities and the possible implications they could have on user security.

The vulnerabilities were detected within version 13.1.9 of REDCap, a platform known for its popularity among universities and research institutions for managing studies containing confidential information. The affected areas within REDCap where these vulnerabilities were found include calendar events, public surveys, and project dashboards.

Researchers involved in the discovery of these vulnerabilities were able to create proof-of-concept exploits for each vulnerable location. By injecting a basic JavaScript payload, they could trigger an alert that displayed the document domain, showcasing the potential for exploitation by cybercriminals.

The implications of these vulnerabilities are far-reaching, as threat actors could exploit them to steal sensitive data, impersonate users, manipulate the REDCap application, and gain unauthorized access to protected information. Given the severity of these risks, users are strongly advised to update their REDCap installations to version 14.2.1 or later, where Vanderbilt University has implemented fixes to address these vulnerabilities and enhance overall security measures.

By taking necessary precautions and ensuring their systems are updated with the latest patches, users can protect themselves from potential exploitation and safeguard their sensitive data from malicious threats. The proactive approach to addressing vulnerabilities is crucial in maintaining the integrity and security of web applications like REDCap, especially in environments where sensitive research data is involved.

Source link

Latest articles

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

 Fortinet on Wednesday said it observed "recent abuse" of a five-year-old security flaw in FortiOS...

More like this

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...