CVE-2025-23113
CVSS 3.1 Score 3.4 of 10 (low)
Details
Published Jan 10, 2025
CWE ID 352
Summary
CVE-2025-23113 is a Cross-Site Request Forgery (CSRF) vulnerability affecting REDCap version 14.9.6. During the upload of a CSV file containing alert configuration, there is no CSRF protection on the logout functionality. An attacker can exploit this by crafting an HTML injection payload in the alert-title of a CSV file. Upon upload, if the victim clicks on the manipulated alert-title, they may be redirected to a phishing website or experience an unintended logout, resulting in terminated sessions and potential data exposure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Vanderbilt