CVE-2013-7222

EPSS 0.62%

Fat Free CRM has fixed token value

發布日:2022/5/17修改日:2024/11/29

描述

`config/initializers/secret_token.rb` in Fat Free CRM before 0.12.1 has a fixed `FatFreeCRM::Application.config.secret_token` value, which makes it easier for remote attackers to spoof signed cookies by referring to the key in the source code.

受影響套件(1)

參考連結(8)