← Back

CVE-2013-4609

nvd nist
Published: Jun 17, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.

Affected (20)

Redcap
1 product
Redcap
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Project Redcap
Version 4.13.18
Version 4.14.5
Version 4.14.6
Version 4.15.0
Version 4.15.1
Version 4.15.2
Version 4.15.3
Version 4.15.4
Version 5.0.0
Version 5.0.1
Version 5.0.2
Version 5.1.0
Version 5.1.1
Version 5.1.2
Vanderbilt
Up to 5.0.3
Version 4.14.0
Version 4.14.1
Version 4.14.2
Version 4.14.3
Version 4.14.4

Related CWEs

Timeline

No history available yet.