RubySec

Providing security resources for the Ruby community

CVE-2019-10226 (fat_free_crm): Fat Free CRM Cross-site Scripting vulnerability

Fat Free CRM Cross-site Scripting vulnerability

Published: May 24, 2022

SECURITY IDENTIFIERS

GEM

fat_free_crm

SEVERITY

CVSS v3.x: 5.4 (Medium)

PATCHED VERSIONS

None available.

DESCRIPTION

HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI.