VYPR

Fatfreecrm

by Fatfreecrm

CVEs (2)

  • CVE-2022-39281MedOct 8, 2022
    risk 0.35cvss 6.5epss 0.02

    fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0.20.1 an authenticated user can perform a remote Denial of Service attack against Fat Free CRM via bucket access. The vulnerability has been patched in commit…

  • CVE-2018-1000842MedDec 20, 2018
    risk 0.33cvss 6.1epss 0.02

    FatFreeCRM version <=0.14.1, >=0.15.0 <=0.15.1, >=0.16.0 <=0.16.3, >=0.17.0 <=0.17.2, ==0.18.0 contains a Cross Site Scripting (XSS) vulnerability in commit 6d60bc8ed010c4eda05d6645c64849f415f68d65 that can result in Javascript execution. This attack appear to be exploitable via…