Unrated severityNVD Advisory· Published Jun 17, 2013· Updated Jun 16, 2026
CVE-2013-4608
CVE-2013-4608
Description
Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View & Descriptive Stats page.
Affected products
20cpe:2.3:a:project-redcap:redcap:4.13.18:*:*:*:*:*:*:*+ 18 more
- cpe:2.3:a:project-redcap:redcap:4.13.18:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:4.14.5:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:4.14.6:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:4.15.0:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:4.15.1:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:4.15.2:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:4.15.3:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:4.15.4:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:5.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:5.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:5.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:5.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:project-redcap:redcap:5.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*range: <=5.0.5
- cpe:2.3:a:vanderbilt:redcap:4.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:vanderbilt:redcap:4.14.1:*:*:*:*:*:*:*
- cpe:2.3:a:vanderbilt:redcap:4.14.2:*:*:*:*:*:*:*
- cpe:2.3:a:vanderbilt:redcap:4.14.3:*:*:*:*:*:*:*
- cpe:2.3:a:vanderbilt:redcap:4.14.4:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.