CVE-2015-1585

Fat Free CRM < 0.13.6 - Cross-Site Request Forgery via Missing Authenticity Token

Title source: llm
STIX 2.1

Description

Fat Free CRM before 0.13.6 allows remote attackers to conduct cross-site request forgery (CSRF) attacks via a request without the authenticity_token, as demonstrated by a crafted HTML page that creates a new administrator account.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534709/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100925

Scores

EPSS 0.0029
EPSS Percentile 52.2%

Details

CWE
CWE-352
Status published
Products (2)
fatfreecrm/fat_free_crm < 0.13.5
rubygems/fat_free_crm 0 - 0.13.6RubyGems
Published Feb 19, 2015
Tracked Since Feb 18, 2026