CVE-2013-7224
Published Jan 2, 2014
Last updated 11 years ago
Overview
- Description
- Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "437226C5-1A19-4BFE-9177-603284DAEADA", "versionEndIncluding": "0.12.0" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ADF154CE-04ED-446E-B2F4-483D7D356975" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34CFB3C8-9C3B-43D8-B946-0EB2FAFD3BF3" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C2B22FC-6FA2-4365-BC71-ED79D914B781" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0108A4ED-2D1F-49C8-88C7-7A074767CFE5" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A5888F1-1D68-4131-ADDC-BBEDB62E74ED" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F5CBECE-E4A4-48A7-8880-D9562378FE22" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33170E54-4CF5-42B2-9F9A-269C26C9FB70" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "890482B9-D9AC-4D10-9764-4E23A112070F" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C652479-AE15-4BAC-AE75-9018FE71AABA" } ], "operator": "OR" } ] } ]