MEDIUM · 6.5

CVE-2013-4609

REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restri...

Vulnerability Description

REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.

CVSS Score

6.5

MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Project-RedcapRedcap4.13.18
VanderbiltRedcap<= 5.0.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-4609?

CVE-2013-4609 is a vulnerability with a CVSS score of 6.5 (MEDIUM). REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restri...

How severe is CVE-2013-4609?

CVE-2013-4609 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4609?

Check the references section above for vendor advisories and patch information. Affected products include: Project-Redcap Redcap, Vanderbilt Redcap.