CVE-2013-7225

Fat Free CRM <0.12.1 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.

Scores

EPSS 0.0053
EPSS Percentile 67.6%

Details

CWE
CWE-89
Status published
Products (11)
fatfreecrm/fat_free_crm 0.9.6
fatfreecrm/fat_free_crm 0.9.7
fatfreecrm/fat_free_crm 0.9.8
fatfreecrm/fat_free_crm 0.9.9
fatfreecrm/fat_free_crm 0.9.10
fatfreecrm/fat_free_crm 0.10.1
fatfreecrm/fat_free_crm 0.11.0
fatfreecrm/fat_free_crm 0.11.1
fatfreecrm/fat_free_crm 0.11.2
fatfreecrm/fat_free_crm < 0.12.0
... and 1 more
Published Jan 02, 2014
Tracked Since Feb 18, 2026