CVE-2013-7224

Fat Free CRM <0.12.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json.

References (6)

Core 6

Scores

EPSS 0.0060
EPSS Percentile 69.7%

Details

CWE
CWE-200
Status published
Products (11)
fatfreecrm/fat_free_crm 0.9.6
fatfreecrm/fat_free_crm 0.9.7
fatfreecrm/fat_free_crm 0.9.8
fatfreecrm/fat_free_crm 0.9.9
fatfreecrm/fat_free_crm 0.9.10
fatfreecrm/fat_free_crm 0.10.1
fatfreecrm/fat_free_crm 0.11.0
fatfreecrm/fat_free_crm 0.11.1
fatfreecrm/fat_free_crm 0.11.2
fatfreecrm/fat_free_crm < 0.12.0
... and 1 more
Published Jan 02, 2014
Tracked Since Feb 18, 2026