Medium severity5.4NVD Advisory· Published Sep 7, 2023· Updated Jul 9, 2026
CVE-2023-37798
CVE-2023-37798
Description
A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the project title parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3= 13.1.35+ 2 more
- (no CPE)range: = 13.1.35
- (no CPE)
- cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*range: <=13.1.35
Patches
Vulnerability mechanics
References
1- www.cyderes.com/blog/cve-2023-37798-stored-cross-site-scripting-in-vanderbilt-redcap/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.