No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Dangerous XSS Bugs in RedCAP Threaten Academic & Scientific Research

July 31, 2024
in Protection
0
Dangerous XSS Bugs in RedCAP Threaten Academic & Scientific Research


Researchers have discovered three cross-site scripting (XSS) vulnerabilities in Research Electronic Data Capture (REDCap), a Web application developed by Vanderbilt University and used for building and managing online surveys and databases for scientific and academic researchers.

The vulnerabilities are tracked as CVE-2024-37394, CVE-2024-37395, and CVE-2024-37396, and they “could allow attackers to execute malicious JavaScript code in victims’ browsers, potentially compromising sensitive data,” according to an advisory from Trustwave’s SpiderLabs.

Researchers there identified the vulnerabilities in multiple locations within version 13.1.9 in REDCap, which is popular in universities and scientific institutions for managing studies that contain private, sensitive information. The vulnerable locations in the platform include calendar events, public surveys, and project dashboards.

“Our researchers developed proof-of-concept exploits for each vulnerable location,” the researchers wrote. “In each case, they were able to inject a simple JavaScript payload that, when triggered, executes an alert displaying the document domain.”

The vulnerabilities could allow threat actors to steal sensitive information, impersonate the victim’s actions, manipulate the REDCap application, and even gain access to protected data.

It’s recommended that users update to REDCap version 14.2.1 or later, where Vanderbilt University has addressed these bugs, to mitigate these flaws. 



Editorial Team

Editorial Team

Related Posts

Three Whoop Band Competitors Are Coming, but I Doubt They'll Be Able to Compete With Whoop's App
Protection

Three Whoop Band Competitors Are Coming, but I Doubt They’ll Be Able to Compete With Whoop’s App

June 17, 2025
Nine Useful Power Tools You Probably Didn’t Know Existed
Protection

Nine Useful Power Tools You Probably Didn’t Know Existed

June 16, 2025
Watch Out for Malicious Unsubscribe Links
Protection

Watch Out for Malicious Unsubscribe Links

June 15, 2025
Why I Would Choose a Steam Deck Over a Nintendo Switch 2
Protection

Why I Would Choose a Steam Deck Over a Nintendo Switch 2

June 14, 2025
Protection

Five of My Favorite YouTube Channels With Free Spin Classes

June 13, 2025
How to Use Each Head on Your Massage Gun Most Effectively
Protection

How to Use Each Head on Your Massage Gun Most Effectively

June 12, 2025
Load More
Next Post
Ciara On Creating Her “Natural Glam” Makeup NARS

Ciara On Creating Her “Natural Glam” Makeup NARS

Popular News

  • Brite Advisors Owner Assumes Control of Mondial Dubai

    Brite Advisors Owner Assumes Control of Mondial Dubai

    0 shares
    Share 0 Tweet 0

Latest News

Insurance investment managers expect to increase allocations to private assets, citing inflation protection.

Insurers eye increased private assets allocations as inflation protection

June 18, 2025
0

Insurance investment managers expect to increase allocations to private assets, citing inflation protection, even as concerns about transparency and reporting...

Compliance is the key to crypto's mass adoption

Compliance is the key to crypto’s mass adoption

June 18, 2025
0

Disclosure: The views and opinions expressed here belong solely to the author and do not represent the views and opinions...

Are You a HENRY? - NerdWallet

Are You a HENRY? – NerdWallet

June 18, 2025
0

The investing information provided on this page is for educational purposes only. NerdWallet, Inc. does not offer advisory or brokerage...

50% off right now at J.Crew & Gap · Primer

50% off right now at J.Crew & Gap · Primer

June 18, 2025
0

Vacation ready. J.Crew and Gap are both doing 50% off right now, which is the kind of math I like...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2024 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2024 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.