CVE-2019-15127

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
21/08/2019
Last modified:
23/08/2019

Description

REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:* 9.3.0 (excluding)