A stored Cross-Site Scripting (XSS)... CVE-2021-42136

3.5 AV AC AU C I A
发布: 2022-04-13
修订: 2024-11-21

A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.

0%
当前有3条漏洞利用/PoC
当前有1条受影响产品信息