CVE-2024-56310
Last modified
CVE-2024-56310 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit this by luring users into clicking on a Project Dashboards name that contains the malicious payload, which triggers a logout request and terminates their session. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit this by luring users into clicking on a Project Dashboards name that contains the malicious payload, which triggers a logout request and terminates their session. This vulnerability stems from the absence of CSRF protections on the logout functionality, allowing malicious actions to be executed without user consent.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vanderbilt | Redcap | <= 14.9.6 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-56310?
How severe is CVE-2024-56310?
How do I fix CVE-2024-56310?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-56299Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2024-5630The Insert or Embed Articulate Content into WordPress plugin…8.8
- CVE-2024-56300Insertion of Sensitive Information Into Sent Data vulnerabil…7.5
- CVE-2024-56301Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2024-56302Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-5631Longse NVR (Network Video Recorder) model NVR3608PGE2W, as w…6
- CVE-2024-56311REDCap through 14.9.6 has a security flaw in the Notes secti…8.8
- CVE-2024-56312A stored cross-site scripting (XSS) vulnerability in the Pro…5.4
- CVE-2024-56313A stored cross-site scripting (XSS) vulnerability in the Cal…5.4
- CVE-2024-56314A stored cross-site scripting (XSS) vulnerability in the Pro…5.4
- CVE-2024-56316In AXESS ACS (Auto Configuration Server) through 5.2.0, unsa…7.5
- CVE-2024-56317In Matter (aka connectedhomeip or Project CHIP) through 1.4.…7.5
Are you affected by CVE-2024-56310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
