Sha256: b22bcaef9311a0e35b97d9dc96cb36c865614e7b7101165e625a68ea8e368e7d
Contents?: true
Size: 625 Bytes
Versions: 5
Compression:
Stored size: 625 Bytes
Contents
--- gem: fat_free_crm osvdb: 118465 cve: 2015-1585 url: http://osvdb.org/show/osvdb/118465 title: Fat Free CRM Gem being vulnerable to CSRF-type attacks date: 2015-02-16 description: | Fat Free CRM contains a flaw as HTTP requests to /admin/users do not require multiple steps, explicit confirmation, or a unique token when performing certain sensitive actions. By tricking a user into following a specially crafted link, a context-dependent attacker can perform a Cross-Site Request Forgery (CSRF / XSRF) attack causing the victim to creating administrative users. cvss_v2: 6.8 patched_versions: - ">= 0.13.6"
Version data entries
5 entries across 5 versions & 2 rubygems