VDB
Sign up
MEDIUM

GHSA-wx7c-8j35-mpg8

Fat Free CRM Cross-Site Request Forgery vulnerability

Quick fix

GHSA-wx7c-8j35-mpg8 — fat_free_crm: upgrade to the fixed version with the command below.

bundle update fat_free_crm

Details

Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/fat_free_crm
Introduced in: 0Fixed in: 0.13.6
Fixbundle update fat_free_crm

References