CVE-2021-42136 is a critical stored Cross-Site Scripting (XSS) vulnerability affecting REDCap versions prior to 11.4.0, specifically within the Missing Data Codes functionality. An authenticated attacker can inject malicious JavaScript code into a Missing Data Code value, which then executes in a user's browser. This allows for high impact to confidentiality, integrity, and availability, with a CVSS score of 9.0, and can be leveraged for Cross-Site Request Forgery (CSRF) attacks to escalate privileges to administrator. While not on the CISA KEV catalog, public exploit code is available via ExploitDB (EDB-50877), though there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.4.0CPE matchmatch criteria | cpe:2.3:a:vanderbilt:redcap:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.