Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v43v-rf94-6vm5

Опубликовано: 11 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. An attacker can exploit this to trick the user that receives the survey into clicking on the field name, which redirects them to a phishing website. Thus, this allows malicious actions to be executed without user consent.

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. An attacker can exploit this to trick the user that receives the survey into clicking on the field name, which redirects them to a phishing website. Thus, this allows malicious actions to be executed without user consent.

EPSS

Процентиль: 25%
0.00085
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.7
nvd
около 1 года назад

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. An attacker can exploit this to trick the user that receives the survey into clicking on the field name, which redirects them to a phishing website. Thus, this allows malicious actions to be executed without user consent.

EPSS

Процентиль: 25%
0.00085
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79