REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
References
Link | Resource |
---|---|
https://gist.github.com/hiennv20/6739606a4d0d25612f5139ec391060b7 | Exploit Third Party Advisory |
https://projectredcap.org/resources/community/ | Vendor Advisory |
https://www.evms.edu/research/resources_services/redcap/redcap_change_log/ | Release Notes |
https://gist.github.com/hiennv20/6739606a4d0d25612f5139ec391060b7 | Exploit Third Party Advisory |
https://projectredcap.org/resources/community/ | Vendor Advisory |
https://www.evms.edu/research/resources_services/redcap/redcap_change_log/ | Release Notes |
Configurations
History
21 Nov 2024, 04:27
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/hiennv20/6739606a4d0d25612f5139ec391060b7 - Exploit, Third Party Advisory | |
References | () https://projectredcap.org/resources/community/ - Vendor Advisory | |
References | () https://www.evms.edu/research/resources_services/redcap/redcap_change_log/ - Release Notes |
Information
Published : 2019-08-17 17:15
Updated : 2024-11-21 04:27
NVD link : CVE-2019-14937
Mitre link : CVE-2019-14937
CVE.ORG link : CVE-2019-14937
JSON object : View
Products Affected
vanderbilt
- redcap
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')