← Back

CVE-2013-7223

nvd nist
Published: Jan 2, 2014Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a protect_from_forgery line in app/controllers/application_controller.rb.

Affected (10)

1 product
Fat Free Crm
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Fatfreecrm
Up to 0.12.0
Version 0.10.1
Version 0.11.0
Version 0.11.1
Version 0.11.2
Version 0.9.10
Version 0.9.6
Version 0.9.7
Version 0.9.8
Version 0.9.9

Timeline

No history available yet.