VDB
Sign up
MEDIUM

GHSA-mcvq-7xjq-46x6

Fat Free CRM contains Cross-site Request Forgery vulnerablilities

Quick fix

GHSA-mcvq-7xjq-46x6 — fat_free_crm: upgrade to the fixed version with the command below.

bundle update fat_free_crm

Details

Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a `protect_from_forgery` line in `app/controllers/application_controller.rb`.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/fat_free_crm
Introduced in: 0Fixed in: 0.12.1
Fixbundle update fat_free_crm

References