Sha256: 9984ba2d1362fb8aa85ec372b6f5ec948f06ade155ed48f27d79c6cceb25236c

Contents?: true

Size: 629 Bytes

Versions: 1

Compression:

Stored size: 629 Bytes

Contents

---
gem: fat_free_crm
osvdb: 110420
cve: 2014-5441
url: https://nvd.nist.gov/vuln/detail/CVE-2014-5441
title: Fat Free CRM Gem contains a javascript cross-site scripting (XSS)
  vulnerability
date: 2014-08-22
description: |
  Fat Free CRM Gem contains a javascript cross-site scripting (XSS)
  vulnerability. When a user is created/updated using a specifically
  crafted username, first name or last name, it is possible for
  arbitrary javascript to be executed on all Fat Free CRM pages.
  This code would be executed for all logged in users.
cvss_v2: 4.3
unaffected_versions:
  - "<= 0.11.0"
patched_versions:
  - ">= 0.13.3"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/fat_free_crm/CVE-2014-5441.yml