important · RCE — REDCap
A public REDCap survey hash can expose unauthenticated server-side code execution.
Affects
REDCap, self-hosted research-data capture and public-survey servers used by healthcare and academic institutions.
Public-survey passthrough routing can reach an unintended Data Import controller, where an attacker-controlled path or stream parameter enters code generation.
Detail and 1 source
Fixed releases exist, but the held evidence is the CNA record rather than an independent public reproducer.