VDB
Sign up
MEDIUM

GHSA-9ggp-5rf4-x7q9

Fat Free CRM vulnerable to SQL Injection

Quick fix

GHSA-9ggp-5rf4-x7q9 — fat_free_crm: upgrade to the fixed version with the command below.

bundle update fat_free_crm

Details

Multiple SQL injection vulnerabilities in `app/controllers/home_controller.rb` in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/fat_free_crm
Introduced in: 0Fixed in: 0.12.1
Fixbundle update fat_free_crm

References