CVE-2014-5441

Fat Free CRM < 0.13.3 - Stored Cross-Site Scripting via User Profile Fields

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) create or (b) edit user action.

Scores

EPSS 0.0030
EPSS Percentile 53.1%

Details

CWE
CWE-79
Status published
Products (7)
fatfreecrm/fat_free_crm 0.11.1
fatfreecrm/fat_free_crm 0.11.2
fatfreecrm/fat_free_crm 0.11.4
fatfreecrm/fat_free_crm 0.12.0
fatfreecrm/fat_free_crm 0.12.1
fatfreecrm/fat_free_crm < 0.13.0
rubygems/fat_free_crm 0.11.1 - 0.13.3RubyGems
Published Sep 12, 2014
Tracked Since Feb 18, 2026