GHSA-wcfx-3m6v-4frg

Suggest an improvement
Source
https://github.com/advisories/GHSA-wcfx-3m6v-4frg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wcfx-3m6v-4frg/GHSA-wcfx-3m6v-4frg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wcfx-3m6v-4frg
Aliases
  • CVE-2014-5441
Published
2022-05-17T04:35:23Z
Modified
2024-12-03T06:04:56Z
Summary
Fat Free CRM subject to Cross-site Scripting
Details

Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) create or (b) edit user action.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-01-23T14:45:13Z",
    "nvd_published_at":  "2014-09-12T14:55:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

RubyGems / fat_free_crm

Package

Name
fat_free_crm
Purl
pkg:gem/fat_free_crm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.11.1
Fixed
0.13.3

Affected versions

0.*
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.13.0
0.13.1
0.13.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wcfx-3m6v-4frg/GHSA-wcfx-3m6v-4frg.json"