CVE-2013-7222

EPSS 0.62%

Fat Free CRM has fixed token value

Published: 5/17/2022Modified: 11/29/2024
Also known as:GHSA-g897-cgfc-7q8v

Description

`config/initializers/secret_token.rb` in Fat Free CRM before 0.12.1 has a fixed `FatFreeCRM::Application.config.secret_token` value, which makes it easier for remote attackers to spoof signed cookies by referring to the key in the source code.

Affected packages (1)

References (8)