CVE-2024-56311
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 22, 2024
Updated: Mar 13, 2025
CWE ID 352
Summary
CVE-2024-56311 is a newly identified vulnerability affecting REDCap versions up to 14.9.6. This issue leads to a Cross-Site Request Forgery (CSRF) attack in the Notes section of calendar events. An attacker can trick users into accessing a malicious calendar event note, which subsequently executes a logout request and terminates the user's session. The root cause of this vulnerability is the absence of CSRF protections on the logout functionality, allowing unauthorized logout actions without user consent.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.