VDB
Sign up
MEDIUM

GHSA-4xq9-vw89-p5cx

Fat Free CRM allows remote attackers to obtain sensitive information via a direct request

Quick fix

GHSA-4xq9-vw89-p5cx — fat_free_crm: upgrade to the fixed version with the command below.

bundle update fat_free_crm

Details

Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for `users/1.json`.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/fat_free_crm
Introduced in: 0Fixed in: 0.12.1
Fixbundle update fat_free_crm

References