Show plain JSON{"id": "CVE-2013-7224", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2014-01-02T14:59:04.110", "references": [{"url": "http://openwall.com/lists/oss-security/2013/12/28/2", "source": "cve@mitre.org"}, {"url": "http://seclists.org/fulldisclosure/2013/Dec/199", "source": "cve@mitre.org"}, {"url": "http://www.phenoelit.org/stuff/ffcrm.txt", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "https://github.com/fatfreecrm/fat_free_crm/commit/cf26a04b356ad2161c4c6160260eb870a3de5328", "source": "cve@mitre.org"}, {"url": "https://github.com/fatfreecrm/fat_free_crm/issues/300", "source": "cve@mitre.org"}, {"url": "https://github.com/fatfreecrm/fat_free_crm/wiki/Fixing-security-vulnerabilities-%2827th-Dec-2013%29", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://openwall.com/lists/oss-security/2013/12/28/2", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://seclists.org/fulldisclosure/2013/Dec/199", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.phenoelit.org/stuff/ffcrm.txt", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://github.com/fatfreecrm/fat_free_crm/commit/cf26a04b356ad2161c4c6160260eb870a3de5328", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://github.com/fatfreecrm/fat_free_crm/issues/300", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://github.com/fatfreecrm/fat_free_crm/wiki/Fixing-security-vulnerabilities-%2827th-Dec-2013%29", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-200"}]}], "descriptions": [{"lang": "en", "value": "Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json."}, {"lang": "es", "value": "Fat Free CRM anterior a 0.12.1 no restringe la serializaci\u00f3n JSON, que permite a atacantes remotos obtener informaci\u00f3n sensible a trav\u00e9s de una petici\u00f3n directa, como lo demuestra una solicitud de users/1.json."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "437226C5-1A19-4BFE-9177-603284DAEADA", "versionEndIncluding": "0.12.0"}, {"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ADF154CE-04ED-446E-B2F4-483D7D356975"}, {"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34CFB3C8-9C3B-43D8-B946-0EB2FAFD3BF3"}, {"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C2B22FC-6FA2-4365-BC71-ED79D914B781"}, {"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0108A4ED-2D1F-49C8-88C7-7A074767CFE5"}, {"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.9.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A5888F1-1D68-4131-ADDC-BBEDB62E74ED"}, {"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F5CBECE-E4A4-48A7-8880-D9562378FE22"}, {"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33170E54-4CF5-42B2-9F9A-269C26C9FB70"}, {"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "890482B9-D9AC-4D10-9764-4E23A112070F"}, {"criteria": "cpe:2.3:a:fatfreecrm:fat_free_crm:0.11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C652479-AE15-4BAC-AE75-9018FE71AABA"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}