VDB
Sign up
MEDIUM

GHSA-f25h-3mj6-4jpg

Fat Free CRM vulnerable to Exposure of Sensitive Information

Quick fix

GHSA-f25h-3mj6-4jpg — fat_free_crm: upgrade to the fixed version with the command below.

bundle update fat_free_crm

Details

Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for `users/1.xml`, a different vulnerability than CVE-2013-7224.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/fat_free_crm
Introduced in: 0Fixed in: 0.12.1
Fixbundle update fat_free_crm

References