REDCap < 14.9.6 Multiple Vulnerabilities

high Web App Scanning Plugin ID 115433

Synopsis

REDCap < 14.9.6 Multiple Vulnerabilities

Description

According to its self-reported version number, the version of REDCap running on the remote host is prior to 14.9.6. It is, therefore, affected by multiple vulnerabilities :

- An HTML injection issue in the Project Dashboard name, allowing an attacker to trigger a logout request through a crafted link, terminating the session of any user clicking on the dashboard name, or to redirect them to a phishing website. (CVE-2024-56310)

- An HTML injection issue in the Notes section of a calendar event, allowing an attacker to trigger a logout request or to redirect a user to a phishing website. (CVE-2024-56311)

- A stored cross-site scripting (XSS) issue in the Project Dashboard name, allowing an authenticated user to inject arbitrary scripts executed when another user opens the dashboard. (CVE-2024-56312)

- A stored cross-site scripting (XSS) issue in the Notes field of a calendar event, allowing an authenticated user to inject arbitrary scripts executed when the event is viewed. (CVE-2024-56313)

- A stored cross-site scripting (XSS) issue in the Project name, allowing an authenticated user to inject arbitrary scripts executed when another user accesses the project. (CVE-2024-56314)

- A stored cross-site scripting (XSS) issue in the message field of the built-in messenger, allowing an authenticated user to inject arbitrary scripts executed when the recipient opens the message. (CVE-2024-56376)

- A stored cross-site scripting (XSS) issue in the Survey Title and Survey Instructions fields, allowing an authenticated user to inject arbitrary scripts executed when a respondent opens the survey. (CVE-2024-56377)

- A reflected cross-site scripting (XSS) issue in the email subject field, reachable through the upload of a CSV file containing a list of alert configurations. (CVE-2025-23110)

- An HTML injection issue via the survey field name, allowing an attacker to redirect a survey respondent to a phishing website. (CVE-2025-23111)

- A stored cross-site scripting (XSS) issue via the survey field name, allowing an authenticated user to inject arbitrary scripts executed when a respondent opens the survey. (CVE-2025-23112)

- An HTML injection issue via the alert-title field, reachable through the upload of a CSV file containing a list of alert configurations, leading to a cross-site request forgery (CSRF) logout of the victim. (CVE-2025-23113)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to REDCap version 14.9.6 or later.

See Also

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2024-56310

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2024-56311

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2024-56312

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2024-56313

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2024-56314

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2024-56376

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2024-56377

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2025-23110

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2025-23111

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2025-23112

https://github.com/ping-oui-no/Vulnerability-Research-CVESS/tree/main/RedCap/CVE-2025-23113

Plugin Details

Severity: High

ID: 115433

Type: Version Based

Published: 8/19/2026

Updated: 8/19/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-23113

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2024-56310

Vulnerability Information

CPE: cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 12/16/2024

Reference Information

CVE: CVE-2024-56310, CVE-2024-56311, CVE-2024-56312, CVE-2024-56313, CVE-2024-56314, CVE-2024-56376, CVE-2024-56377, CVE-2025-23110, CVE-2025-23111, CVE-2025-23112, CVE-2025-23113