CVE-2013-7222

Fat Free CRM <0.12.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

config/initializers/secret_token.rb in Fat Free CRM before 0.12.1 has a fixed FatFreeCRM::Application.config.secret_token value, which makes it easier for remote attackers to spoof signed cookies by referring to the key in the source code.

References (6)

Core 6

Scores

EPSS 0.0062
EPSS Percentile 70.3%

Details

CWE
CWE-310
Status published
Products (11)
fatfreecrm/fat_free_crm 0.9.6
fatfreecrm/fat_free_crm 0.9.7
fatfreecrm/fat_free_crm 0.9.8
fatfreecrm/fat_free_crm 0.9.9
fatfreecrm/fat_free_crm 0.9.10
fatfreecrm/fat_free_crm 0.10.1
fatfreecrm/fat_free_crm 0.11.0
fatfreecrm/fat_free_crm 0.11.1
fatfreecrm/fat_free_crm 0.11.2
fatfreecrm/fat_free_crm < 0.12.0
... and 1 more
Published Jan 02, 2014
Tracked Since Feb 18, 2026