CVE-2024-56310
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-56310 is a newly identified vulnerability affecting REDCap software up to version 14.9.6. This issue exposes users to a Cross-Site Request Forgery (CSRF) attack through the Project Dashboards feature. Malicious actors can manipulate Project Dashboard names to include malicious payloads, which, when clicked by unsuspecting users, trigger a logout request and terminate their sessions. The root cause of this vulnerability lies in the absence of CSRF protections on the logout functionality, enabling unauthorized actions to be carried out without user consent.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.