CVE-2013-7249
02.01.2014, 14:59
Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.xml, a different vulnerability than CVE-2013-7224.Enginsight
Vendor | Product | Version |
---|---|---|
fatfreecrm | fat_free_crm | 𝑥 ≤ 0.12.0 |
fatfreecrm | fat_free_crm | 0.9.6 |
fatfreecrm | fat_free_crm | 0.9.7 |
fatfreecrm | fat_free_crm | 0.9.8 |
fatfreecrm | fat_free_crm | 0.9.9 |
fatfreecrm | fat_free_crm | 0.9.10 |
fatfreecrm | fat_free_crm | 0.10.1 |
fatfreecrm | fat_free_crm | 0.11.0 |
fatfreecrm | fat_free_crm | 0.11.1 |
fatfreecrm | fat_free_crm | 0.11.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References