CVE-2024-56313
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Dec 22, 2024
Updated: Mar 18, 2025
CWE ID 79
Summary
CVE-2024-56313 is a stored XSS vulnerability affecting the Calendar feature in REDCap versions up to 14.9.6. This issue allows authenticated users to inject malicious scripts into the Notes field of a calendar event. Upon viewing the event, the crafted payload is executed, potentially enabling the execution of arbitrary web scripts, posing a serious security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.