Vulnerability Description
REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Project-Redcap | Redcap | 4.13.18 |
| Vanderbilt | Redcap | <= 5.0.3 |
Related Weaknesses (CWE)
References
- http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf
- http://ctsi.psu.edu/wp-content/uploads/2013/03/REDCap-Release-Notes-Version5.pdf
FAQ
What is CVE-2013-4609?
CVE-2013-4609 is a vulnerability with a CVSS score of 6.5 (MEDIUM). REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restri...
How severe is CVE-2013-4609?
CVE-2013-4609 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4609?
Check the references section above for vendor advisories and patch information. Affected products include: Project-Redcap Redcap, Vanderbilt Redcap.