Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary web script or HTML via uppercase characters in JavaScript events within user-defined labels.
Software | From | Fixed in |
---|---|---|
vanderbilt / redcap | - | 4.14.2.x |
vanderbilt / redcap | 4.14.0 | 4.14.0.x |
vanderbilt / redcap | 4.14.1 | 4.14.1.x |