CVE-2023-37361: Vanderbilt Redcap
Low severity, CVSS 2.7. EPSS: 0.6% chance of exploitation in the next 30 days.
REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomization.
Affected products
- Vanderbilt Redcap: before 12.3.2 (fixed in 12.3.2); before 12.0.26 (fixed in 12.0.26)
Published 2023-07-25. Last modified 2026-06-17.