Sha256: b22bcaef9311a0e35b97d9dc96cb36c865614e7b7101165e625a68ea8e368e7d

Contents?: true

Size: 625 Bytes

Versions: 5

Compression:

Stored size: 625 Bytes

Contents

---
gem: fat_free_crm
osvdb: 118465
cve: 2015-1585
url: http://osvdb.org/show/osvdb/118465
title: Fat Free CRM Gem being vulnerable to CSRF-type attacks
date: 2015-02-16
description: |
  Fat Free CRM contains a flaw as HTTP requests to /admin/users do not require
  multiple steps, explicit confirmation, or a unique token when performing
  certain sensitive actions. By tricking a user into following a specially
  crafted link, a context-dependent attacker can perform a Cross-Site Request
  Forgery (CSRF / XSRF) attack causing the victim to creating administrative
  users.
cvss_v2: 6.8
patched_versions:
  - ">= 0.13.6"

Version data entries

5 entries across 5 versions & 2 rubygems

Version Path
bundler-budit-0.6.2 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-118465.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-118465.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-118465.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-118465.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/fat_free_crm/OSVDB-118465.yml