MEDIUM
GHSA-9ggp-5rf4-x7q9
Fat Free CRM vulnerable to SQL Injection
Quick fix
GHSA-9ggp-5rf4-x7q9 — fat_free_crm: upgrade to the fixed version with the command below.
bundle update fat_free_crmDetails
Multiple SQL injection vulnerabilities in `app/controllers/home_controller.rb` in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2013-7225[ADVISORY]
- https://github.com/fatfreecrm/fat_free_crm/issues/300[WEB]
- https://github.com/fatfreecrm/fat_free_crm/commit/078035f1ef73ed85285ac9d128c3c5f670cef066[WEB]
- https://github.com/fatfreecrm/fat_free_crm/commit/d4b2de81a4d8c1b201482edcb2488ed9280a65fd[WEB]
- https://github.com/fatfreecrm/fat_free_crm[PACKAGE]
- https://github.com/fatfreecrm/fat_free_crm/wiki/Fixing-security-vulnerabilities-%2827th-Dec-2013%29[WEB]
- http://openwall.com/lists/oss-security/2013/12/28/2[WEB]
- http://seclists.org/fulldisclosure/2013/Dec/199[WEB]