CVE-2013-7225

EPSS 0.53%

Fat Free CRM vulnerable to SQL Injection

Published: 5/17/2022Modified: 12/3/2024
Also known as:GHSA-9ggp-5rf4-x7q9

Description

Multiple SQL injection vulnerabilities in `app/controllers/home_controller.rb` in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.

Affected packages (1)

References (8)