Vulnerability CVE-2022-42715


Published: 2022-10-12

Description:
A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, trigger arbitrary JavaScript code execution.

 References:
https://redcap.med.usc.edu/_shib/assets/ChangeLog_Standard.pdf
https://www.evms.edu/research/resources_services/redcap/redcap_change_log/

Copyright 2026, cxsecurity.com

 

Back to Top