--- gem: fat_free_crm osvdb: 101448 cve: 2013-7225 url: http://osvdb.org/show/osvdb/101448 title: Fat Free CRM Gem for Ruby allows remote attackers to inject or manipulate SQL queries date: 2013-12-24 description: | Fat Free CRM contains a flaw that may allow carrying out an SQL injection attack. The issue is due to the app/controllers/home_controller.rb script not properly sanitizing user-supplied input to the 'state' parameter or input passed via comments and emails. This may allow a remote attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data. cvss_v2: 6.5 patched_versions: - ">= 0.13.0" - "~> 0.12.1"