5
CVSSv2

CVE-2013-7224

Published: 02/01/2014 Updated: 03/01/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Fat Free CRM prior to 0.12.1 does not restrict JSON serialization, which allows remote malicious users to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json.

Vulnerable Product Search on Vulmon Subscribe to Product

fatfreecrm fat free crm

fatfreecrm fat free crm 0.9.8

fatfreecrm fat free crm 0.9.6

fatfreecrm fat free crm 0.11.1

fatfreecrm fat free crm 0.11.0

fatfreecrm fat free crm 0.10.1

fatfreecrm fat free crm 0.9.10

fatfreecrm fat free crm 0.11.2

fatfreecrm fat free crm 0.9.9

fatfreecrm fat free crm 0.9.7