CVE-2014-5441
EPSS 0.30%Fat Free CRM subject to Cross-site Scripting
發布日:2022/5/17修改日:2024/12/3
描述
Multiple cross-site scripting (XSS) vulnerabilities in `app/views/layouts/application.html.haml` in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) create or (b) edit user action.
受影響套件(1)
- RubyGems/fat_free_crm>= 0.11.1, < 0.13.3
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2014-5441
- PATCHhttps://github.com/fatfreecrm/fat_free_crm
- WEBhttp://packetstormsecurity.com/files/127978/Fatt-Free-CRM-Cross-Site-Scripting.html
- WEBhttps://github.com/fatfreecrm/fat_free_crm/commit/95464495f1e3e714d5c295fe621af5d2e0d4238d
- WEBhttps://github.com/fatfreecrm/fat_free_crm/wiki/XSS-vulnerability-%2826th-August-2014%29