Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6gp-fj2f-fv4w

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.

REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.

EPSS

Процентиль: 41%
0.00191
Низкий

Связанные уязвимости

nvd
больше 12 лет назад

REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.

EPSS

Процентиль: 41%
0.00191
Низкий