CVE-2021-42136 EXPLOIT
9.0
CRITICAL · CVSS 3.1 · EPSS 4.7% (pctl 91)
Patch early
A public exploit exists.
Description
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute JavaScript code in the client's browser by storing said code as a Missing Data Code value. This can then be leveraged to execute a Cross-Site Request Forgery attack to escalate privileges to administrator.
Scoring
| CVSS | 9.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
| EPSS | 4.66% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-04-13 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| vanderbilt | redcap |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | REDCap 11.3.9 - Stored Cross Site Scripting | 2022-04-19 |
References
- http://packetstormsecurity.com/files/166723/REDCap-Cross-Site-Scripting.html
- https://redcap.med.usc.edu/_shib/assets/ChangeLog_Standard.pdf
- https://www.project-redcap.org/
- http://packetstormsecurity.com/files/166723/REDCap-Cross-Site-Scripting.html
- https://redcap.med.usc.edu/_shib/assets/ChangeLog_Standard.pdf
- https://www.project-redcap.org/
→ the Explorer · watch your stack · NVD