6.5
CVSSv2

CVE-2013-7225

Published: 02/01/2014 Updated: 03/01/2014
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM prior to 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fatfreecrm fat free crm 0.11.0

fatfreecrm fat free crm 0.9.10

fatfreecrm fat free crm

fatfreecrm fat free crm 0.11.2

fatfreecrm fat free crm 0.11.1

fatfreecrm fat free crm 0.9.8

fatfreecrm fat free crm 0.9.7

fatfreecrm fat free crm 0.9.6

fatfreecrm fat free crm 0.10.1

fatfreecrm fat free crm 0.9.9