REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomization.
2023-07-25T01:15:09.377
2024-11-21T08:11:34.950
Modified
CVSSv3.1: 2.7 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | vanderbilt | redcap | < 12.3.2 | Yes |
| Application | vanderbilt | redcap | < 12.0.26 | Yes |