cbcvebase.
CVE-2022-42715
published 2022-10-12

CVE-2022-42715: A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger…

PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.70%
48.4th percentile
A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger arbitrary JavaScript code execution.

Affected

2 ranges
VendorProductVersion rangeFixed in
vanderbiltredcap< 12.4.1812.4.18
vanderbiltredcap>= 12.5.0 < 12.5.1112.5.11
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.