Medium severity6.5NVD Advisory· Published Mar 21, 2024· Updated Jun 17, 2026
CVE-2023-38825
CVE-2023-38825
Description
SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mechanism in MyCapMobileApp/update.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:*range: <13.8.0
- (no CPE)range: <13.8.0
- Vanderbilt/RECapdescription
Patches
Vulnerability mechanics
References
1- www.project-redcap.orgnvdProduct
News mentions
0No linked articles in our index yet.