CVE-2013-7223

Fat Free CRM < 0.12.1 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a protect_from_forgery line in app/controllers/application_controller.rb.

References (6)

Core 6

Scores

EPSS 0.0029
EPSS Percentile 52.9%

Details

CWE
CWE-352
Status published
Products (11)
fatfreecrm/fat_free_crm 0.9.6
fatfreecrm/fat_free_crm 0.9.7
fatfreecrm/fat_free_crm 0.9.8
fatfreecrm/fat_free_crm 0.9.9
fatfreecrm/fat_free_crm 0.9.10
fatfreecrm/fat_free_crm 0.10.1
fatfreecrm/fat_free_crm 0.11.0
fatfreecrm/fat_free_crm 0.11.1
fatfreecrm/fat_free_crm 0.11.2
fatfreecrm/fat_free_crm < 0.12.0
... and 1 more
Published Jan 02, 2014
Tracked Since Feb 18, 2026