No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Dangerous XSS Bugs in RedCAP Threaten Academic & Scientific Research

July 31, 2024
in Protection
0
Dangerous XSS Bugs in RedCAP Threaten Academic & Scientific Research


Researchers have discovered three cross-site scripting (XSS) vulnerabilities in Research Electronic Data Capture (REDCap), a Web application developed by Vanderbilt University and used for building and managing online surveys and databases for scientific and academic researchers.

The vulnerabilities are tracked as CVE-2024-37394, CVE-2024-37395, and CVE-2024-37396, and they “could allow attackers to execute malicious JavaScript code in victims’ browsers, potentially compromising sensitive data,” according to an advisory from Trustwave’s SpiderLabs.

Researchers there identified the vulnerabilities in multiple locations within version 13.1.9 in REDCap, which is popular in universities and scientific institutions for managing studies that contain private, sensitive information. The vulnerable locations in the platform include calendar events, public surveys, and project dashboards.

“Our researchers developed proof-of-concept exploits for each vulnerable location,” the researchers wrote. “In each case, they were able to inject a simple JavaScript payload that, when triggered, executes an alert displaying the document domain.”

The vulnerabilities could allow threat actors to steal sensitive information, impersonate the victim’s actions, manipulate the REDCap application, and even gain access to protected data.

It’s recommended that users update to REDCap version 14.2.1 or later, where Vanderbilt University has addressed these bugs, to mitigate these flaws. 



Editorial Team

Editorial Team

Related Posts

My Five Favorite Things About the Garmin Forerunner 970 (so Far)
Protection

My Five Favorite Things About the Garmin Forerunner 970 (so Far)

April 4, 2026
The Bowers & Wilkins Px7 S3 Headphones Are 42% Off Right Now
Protection

The Bowers & Wilkins Px7 S3 Headphones Are 42% Off Right Now

April 4, 2026
This Powerful LG 23,500 BTU Smart Air Conditioner Is on Sale for Just $600 Right Now
Protection

This Powerful LG 23,500 BTU Smart Air Conditioner Is on Sale for Just $600 Right Now

April 4, 2026
The CMF Watch 3 Pro With AI-Powered Tracking Is on Sale for $45 Right Now
Protection

The CMF Watch 3 Pro With AI-Powered Tracking Is on Sale for $45 Right Now

April 4, 2026
10 Hacks Every Apple Vision Pro User Should Know
Protection

10 Hacks Every Apple Vision Pro User Should Know

April 4, 2026
Why ‘Open Platform’ Is the Next Big Frontier for Smart Glasses
Protection

Why ‘Open Platform’ Is the Next Big Frontier for Smart Glasses

April 3, 2026
Load More
Next Post
Ciara On Creating Her “Natural Glam” Makeup NARS

Ciara On Creating Her “Natural Glam” Makeup NARS

Popular News

  • Gasoil is spiking more than crude. What it is and why prices are soaring amid Iran conflict

    Gasoil is spiking more than crude. What it is and why prices are soaring amid Iran conflict

    0 shares
    Share 0 Tweet 0
  • Exclusive-Prior to Iran attacks, CIA assessed Khamenei would be replaced by IRCG elements if killed, sources say

    0 shares
    Share 0 Tweet 0
  • TOBY WALNE: The 13 items that reveal ‘car boot sale rubbish’ is being sold at huge mark-ups on online antique giant Vinted… so can you STILL find a bargain there?

    0 shares
    Share 0 Tweet 0
  • Blockchain Association Calls For Modernized Crypto Tax Rules In New Release

    0 shares
    Share 0 Tweet 0
  • The best bank accounts: Compare switch offers and more perks

    0 shares
    Share 0 Tweet 0

Latest News

EU tariffs on US goods by September 30 loom as Trump escalates trade tensions

EU tariffs on US goods by September 30 loom as Trump escalates trade tensions

April 4, 2026
0

Trump’s reputation as a dealmaker challenging major powers stirs trade tensions. The odds of the EU imposing retaliatory tariffs on...

Metaplanet’s Q1 Buying Spree Earns It Top 3 Bitcoin Treasury Status

Metaplanet’s Q1 Buying Spree Earns It Top 3 Bitcoin Treasury Status

April 4, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Tokyo-listed investment firm Metaplanet generated close to...

My Five Favorite Things About the Garmin Forerunner 970 (so Far)

My Five Favorite Things About the Garmin Forerunner 970 (so Far)

April 4, 2026
0

We may earn a commission from links on this page. The Garmin Forerunner 970 is the newest and best Forerunner...

Bitcoin ETFs Will Be Bigger Than Gold ETFs, Says ETF Analyst

Bitcoin ETFs Will Be Bigger Than Gold ETFs, Says ETF Analyst

April 4, 2026
0

Spot Bitcoin exchange-traded funds (ETFs) could surpass gold ETFs in total assets under management (AUM) as investor demand expands beyond...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.