REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-6034 REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T00:34:52.407Z

Reserved: 2019-08-11T00:00:00

Link: CVE-2019-14937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-17T17:15:10.057

Modified: 2024-11-21T04:27:43.447

Link: CVE-2019-14937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses