CVE-2013-7249

Fat Free CRM <0.12.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.xml, a different vulnerability than CVE-2013-7224.

References (6)

Core 6

Scores

EPSS 0.0062
EPSS Percentile 70.3%

Details

CWE
CWE-200
Status published
Products (11)
fatfreecrm/fat_free_crm 0.9.6
fatfreecrm/fat_free_crm 0.9.7
fatfreecrm/fat_free_crm 0.9.8
fatfreecrm/fat_free_crm 0.9.9
fatfreecrm/fat_free_crm 0.9.10
fatfreecrm/fat_free_crm 0.10.1
fatfreecrm/fat_free_crm 0.11.0
fatfreecrm/fat_free_crm 0.11.1
fatfreecrm/fat_free_crm 0.11.2
fatfreecrm/fat_free_crm < 0.12.0
... and 1 more
Published Jan 02, 2014
Tracked Since Feb 18, 2026