VendorsFat Free CRMfat_free_crm0.12.1
Vulnerabilities

Fat Free CRM Fat Free CRM 0.12.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2014-5441
Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) create or (b) edit user action.
Published 2014-09-12 · Modified
4.3EPSS 0.019