← Back to CVE List

CVE-2019-14937

Published: 2019-08-17T17:15Z
Last Modified: 2024-11-21T04:27Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt