CVE-2014-5441
Published Sep 12, 2014
Last updated 10 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in app/views/layouts/application.html.haml in Fat Free CRM before 0.13.3 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name in a (a) create or (b) edit user action.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53E3463D-EB2A-4BCC-A64F-9ACE8E537237", "versionEndIncluding": "0.13.0" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "890482B9-D9AC-4D10-9764-4E23A112070F" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C652479-AE15-4BAC-AE75-9018FE71AABA" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.11.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B386ACB6-01C7-435D-A2F2-67FF497AF21C" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.12.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22E08161-69D1-4329-8931-8568EC700851" }, { "criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.12.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D51C7C7E-07CB-4425-A620-7C323E413B1F" } ], "operator": "OR" } ] } ]