Vulnerability Details CVE-2019-14937
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.2%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 6.0
Products affected by CVE-2019-14937
-
cpe:2.3:a:vanderbilt:redcap:8.11.5
-
cpe:2.3:a:vanderbilt:redcap:8.11.6
-
cpe:2.3:a:vanderbilt:redcap:9.0
-
cpe:2.3:a:vanderbilt:redcap:9.1
-
cpe:2.3:a:vanderbilt:redcap:9.1.2
-
cpe:2.3:a:vanderbilt:redcap:9.2.0
-
cpe:2.3:a:vanderbilt:redcap:9.2.1
-
cpe:2.3:a:vanderbilt:redcap:9.2.2
-
cpe:2.3:a:vanderbilt:redcap:9.2.3
-
cpe:2.3:a:vanderbilt:redcap:9.2.4
-
cpe:2.3:a:vanderbilt:redcap:9.2.5