logo

Dangerous XSS Bugs in RedCAP Threaten Academic & Scientific Research

ID: b8787636-d3d7-542e-aa2c-6c7b892d1322

STIX ID: report--b8787636-d3d7-542e-aa2c-6c7b892d1322

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-07-31

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Researchers identified three XSS vulnerabilities in REDCap (CVE-2024-37394, CVE-2024-37395, CVE-2024-37396) affecting version 13.1.9 in calendar events, public surveys, and project dashboards; proof-of-concept JavaScript payloads were developed and vendors recommend upgrading to REDCap 14.2.1 or later to mitigate the flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.