Steve Kenworthy

2 exploits Active since Jan 2014
CVE-2013-7225 WRITEUP WRITEUP
Fat Free CRM <0.12.1 - SQL Injection
Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.
CVE-2022-39281 WRITEUP MEDIUM WRITEUP
Fatfreecrm < 0.20.1 - Improper Input Validation
fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0.20.1 an authenticated user can perform a remote Denial of Service attack against Fat Free CRM via bucket access. The vulnerability has been patched in commit `c85a254` and will be available in release `0.20.1`. Users are advised to upgrade or to manually apply patch `c85a254`. There are no known workarounds for this issue.
CVSS 6.5