CVE-2017-7351: Vanderbilt Redcap

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.

Affected products

  • Vanderbilt Redcap: from 7.0.0, before 7.0.11 (fixed in 7.0.11)

Published 2018-02-08. Last modified 2026-06-17.