CVE-2025-23113

CVSS 3.1 Score 3.4 of 10 (low)

Details

Published Jan 10, 2025
CWE ID 352

Summary

CVE-2025-23113 is a Cross-Site Request Forgery (CSRF) vulnerability affecting REDCap version 14.9.6. During the upload of a CSV file containing alert configuration, there is no CSRF protection on the logout functionality. An attacker can exploit this by crafting an HTML injection payload in the alert-title of a CSV file. Upon upload, if the victim clicks on the manipulated alert-title, they may be redirected to a phishing website or experience an unintended logout, resulting in terminated sessions and potential data exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share