Sha256: ad0a1fcb9596b5144c5a991c7d408f3d1f52d68c5436337195a09dbecfec9204

Contents?: true

Size: 782 Bytes

Versions: 5

Compression:

Stored size: 782 Bytes

Contents

---
gem: fat_free_crm
osvdb: 101446
cve: 2013-7223
url: http://osvdb.org/show/osvdb/101446
title: Fat Free CRM Gem for Ruby contains multiple cross-site request forgery
  (CSRF) vulnerabilities
date: 2013-12-24
description: |
  Fat Free CRM contains a flaw as the application is missing the protect_from_forgery
  statement, therefore HTTP requests to app/controllers/application_controller.rb
  do not require multiple steps, explicit confirmation, or a unique token when
  performing certain sensitive actions. By tricking a user into following a specially
  crafted link, a context-dependent attacker can perform a Cross-Site Request Forgery
  (CSRF / XSRF) attack causing the victim to perform unspecified actions.
cvss_v2: 6.8
patched_versions:
  - ">= 0.13.0"
  - "~> 0.12.1"

Version data entries

5 entries across 5 versions & 2 rubygems

Version Path
bundler-budit-0.6.2 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101446.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101446.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101446.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101446.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-101446.yml